๐ฉ๐ช
psauxit
2026-08-31 07:49:16
(2 days ago)
Fail2Ban - NGINX heavily bad-bot, possible vulnerability scanning and excessive crawling/scraping
Bad Web Bot
Web App Attack
Hacking
Web Spam
๐บ๐ธ
TPI-Abuse
2026-08-31 03:58:11
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 129.146.49.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.146.49.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:58:07.402595 2026] [security2:error] [pid 4645:tid 4645] [client 129.146.49.182:59199] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bahamascruisersguide.com|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bahamascruisersguide.com"] [uri "/Blogs-Websites/snowbirdscompassrose.blogspot.com"] [unique_id "apT7z-unnXcAQTZ0h7bJKAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-30 14:05:30
(3 days ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 11:17:42
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 129.146.49.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 129.146.49.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 07:17:34.603379 2026] [security2:error] [pid 28938:tid 28938] [client 129.146.49.182:56515] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.markgiffin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.markgiffin.com"] [uri "/blog/wp-json/wp/v2/users/1"] [unique_id "apQRTveyj42UQbSQgHgdEQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 15:08:05
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 129.146.49.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.146.49.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 11:08:01.890667 2026] [security2:error] [pid 5150:tid 5150] [client 129.146.49.182:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.swarnar.com|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.swarnar.com"] [uri "/justswarna.blogspot.com"] [unique_id "apL10YAVet8U8krAUk91VgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-29 08:38:05
(4 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /xmlrpc.php | 2026-08-29 08:38 UTC
show less
Hacking
Web App Attack
๐จ๐ญ
YF
2026-08-29 02:00:53
(4 days ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-29 01:48:26
(5 days ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 15:06:04
(5 days ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
๐ฉ๐ช
darkfader
2026-08-28 07:58:00
(5 days ago)
Web App Attack
๐ฎ๐ณ
dineshskt4all
2026-08-28 05:59:21
(5 days ago)
129.146.49.182 - - [28/Aug/2026:05:59:17 +0000] "GET /robots.txt HTTP/1.1" 200 280 "-" "AteveSearchS ...
show more
129.146.49.182 - - [28/Aug/2026:05:59:17 +0000] "GET /robots.txt HTTP/1.1" 200 280 "-" "AteveSearchSourceUrlDiscovery/0.1 (+mailto:[email protected] )"
...
show less
IoT Targeted
๐ฎ๐น
VHosting
2026-08-27 22:10:05
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack