๐บ๐ธ
TPI-Abuse
2025-12-07 19:54:54
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 14:54:49.424294 2025] [security2:error] [pid 5839:tid 5839] [client 122.155.7.202:45988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adventiststoday.com"] [uri "/.env"] [unique_id "aTXbiYWs_Aral0e8RjpijAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 18:39:13
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 13:39:07.119325 2025] [security2:error] [pid 7057:tid 7075] [client 122.155.7.202:54868] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eliteproductions.tv|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eliteproductions.tv"] [uri "/site.bak"] [unique_id "aTXJy2idXD5kbCdIUUPQ9wAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2025-12-06 02:35:54
(8 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-05 09:50:41
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 04:50:35.960921 2025] [security2:error] [pid 17936:tid 17936] [client 122.155.7.202:52862] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||804websolutions.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "804websolutions.com"] [uri "/0.bak"] [unique_id "aTKq66PSitkSYAJ1wN_oDQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-04 23:45:19
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 18:45:12.530316 2025] [security2:error] [pid 29890:tid 29890] [client 122.155.7.202:54360] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clinegroupmarketplace.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clinegroupmarketplace.com"] [uri "/htdocs.bak"] [unique_id "aTIdCD4RwVMT_U3OXit-ZwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-04 08:18:50
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 03:18:46.282896 2025] [security2:error] [pid 3704:tid 3704] [client 122.155.7.202:58330] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||memorialcityzen.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "memorialcityzen.com"] [uri "/1.bak"] [unique_id "aTFD5sEprfrUb0DL8ny4IQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-11-27 18:59:41
(9 months ago)
(apache_scanners-2) Failed apache-scanners trigger with match [redacted])
Port Scan
๐ฉ๐ช
LRob
2025-11-23 23:00:32
(9 months ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
LRob
2025-11-23 21:15:27
(9 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฉ๐ช
Petros Stefanakis
2025-11-23 19:28:06
(9 months ago)
(mod_security) mod_security triggered on hostname [redacted] 122.155.7.202 (TH/Thailand/ns1-1557202. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 122.155.7.202 (TH/Thailand/ns1-1557202.dragonhispeed.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-11-23 18:36:53
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 13:36:46.052142 2025] [security2:error] [pid 8314:tid 8314] [client 122.155.7.202:44812] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||veneerdent.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "veneerdent.com"] [uri "/httpd.bak"] [unique_id "aSNUPp5SYdee7sS9cPQ_ZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
YF
2025-11-23 07:05:02
(9 months ago)
Attempted access to sensitive files
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-20 19:56:03
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 122.155.7.202 (ns1-1557202.dragonhispeed.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 14:55:57.213720 2025] [security2:error] [pid 4871:tid 4871] [client 122.155.7.202:43546] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||myouenji.org|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "myouenji.org"] [uri "/myouenji.bak"] [unique_id "aR9yTenJFXSVcHU6w6hdegAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-20 16:55:53
(9 months ago)
122.155.7.202 - - [20/Nov/2025:17:55:29 +0100] "GET /backup.tar.gz HTTP/1.1" 200 6572 "https://www.f ...
show more
122.155.7.202 - - [20/Nov/2025:17:55:29 +0100] "GET /backup.tar.gz HTTP/1.1" 200 6572 "https://www.free-reseau.com/backup.tar.gz" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
122.155.7.202 - - [20/Nov/2025:17:55:52 +0100] "GET /db/ HTTP/1.1" 200 4428 "https://www.free-reseau.com/db/" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Web App Attack
Anonymous
2025-11-20 15:26:19
(9 months ago)
122.155.7.202 - - [20/Nov/2025:16:18:34 +0100] "GET /var/pma/ HTTP/1.1" 200 4437 "https://www.free-r ...
show more
122.155.7.202 - - [20/Nov/2025:16:18:34 +0100] "GET /var/pma/ HTTP/1.1" 200 4437 "https://www.free-reseau.com/var/pma/" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
122.155.7.202 - - [20/Nov/2025:16:22:33 +0100] "GET /PMA/ HTTP/1.1" 200 4430 "https://www.free-reseau.com/PMA/" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
122.155.7.202 - - [20/Nov/2025:16:26:18 +0100] "GET /admin/pma/ HTTP/1.1" 200 4434 "https://www.free-reseau.com/admin/pma/" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Web App Attack