๐ฌ๐ง
thetomtaylor.co.uk
2026-06-26 04:07:02
(2 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
rdpguard.com
2026-06-26 03:52:58
(2 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ง๐ช
cmbplf
2026-06-26 01:26:12
(4 hours ago)
172 requests with url.path *config.json
163 requests with url.path *.php.bak
147 requests with ur ...
show more
172 requests with url.path *config.json
163 requests with url.path *.php.bak
147 requests with url.path *sftp.json
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-24 16:40:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 12:40:35.005780 2026] [security2:error] [pid 24477:tid 24477] [client 129.212.224.184:63419] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||86mountaineers.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "86mountaineers.net"] [uri "/ftp.ini"] [unique_id "ajwIg39vZwfQunKMOO_gqAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 15:03:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 11:03:36.062111 2026] [security2:error] [pid 16054:tid 16054] [client 129.212.224.184:60973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "804web.net"] [uri "/sftp-config.json"] [unique_id "ajvxyNKJ74jI3tbuIlXh9gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-24 14:28:02
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 14:25:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 10:25:05.827878 2026] [security2:error] [pid 1153:tid 1247] [client 129.212.224.184:63683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "7sons.net"] [uri "/sftp-config.json"] [unique_id "ajvowW0IlBVWiZrRCQatOAAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 12:56:39
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 08:56:34.830207 2026] [security2:error] [pid 4284:tid 4284] [client 129.212.224.184:60017] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "789-bid.net"] [uri "/ftp.ini"] [unique_id "ajvUApQMoMPnfsFW1l-qMwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
lufi
2026-06-23 22:56:38
(2 days ago)
2026-06-24T00:56:38+02:00 lufischer04 ids442 2026-06-24 00:56:38 129.212.224.184: blacklistedPath: / ...
show more
2026-06-24T00:56:38+02:00 lufischer04 ids442 2026-06-24 00:56:38 129.212.224.184: blacklistedPath: /.vscode/ftp-sync.json
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-23 17:06:02
(2 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01]
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-23 16:07:02
(2 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐ฎ๐ฉ
Burayot
2026-06-22 14:30:41
(3 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 129.212.224.184 (SG/Singapore/-): 2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 129.212.224.184 (SG/Singapore/-): 2 in the last 3600 secs
show less
Web App Attack
๐จ๐ญ
4server
2026-06-22 13:14:23
(3 days ago)
''
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 12:56:09
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.224.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 08:56:02.534594 2026] [security2:error] [pid 18679:tid 18679] [client 129.212.224.184:51871] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||4ehardware.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "4ehardware.net"] [uri "/ftp.ini"] [unique_id "ajkw4kWUkGODMy5GH23P_wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
lufi
2026-06-22 11:10:29
(3 days ago)
2026-06-22T13:10:28+02:00 lufischer04 ids442 2026-06-22 13:10:28 129.212.224.184: blacklistedPath: / ...
show more
2026-06-22T13:10:28+02:00 lufischer04 ids442 2026-06-22 13:10:28 129.212.224.184: blacklistedPath: /.vscode/ftp-sync.json
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack