๐ซ๐ท
matthieul.dev
2026-07-14 10:05:42
(2 weeks ago)
Blocked by os-abuseipdb; 5 hits, proto=tcp, ports=59261
Port Scan
Brute-Force
๐บ๐ธ
xmission.com
2026-07-06 13:40:39
(3 weeks ago)
Blocked by UFW (TCP on 1)
Source port: 50349
TTL: 115
Packet length: 52
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 1)
Source port: 50349
TTL: 115
Packet length: 52
TOS: 0x08
This report (for 149.22.87.41) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
EGP Abuse Dept
2026-07-03 01:15:12
(4 weeks ago)
Scanning for port/service exploits on tpc-027.mach3builders.nl
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-27 19:39:39
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 15:39:31.783533 2026] [security2:error] [pid 19127:tid 19127] [client 149.22.87.41:59855] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ww-bbs.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ww-bbs.com"] [uri "/39/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akAm8yD7MKqDYJHokNwc4QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 19:12:47
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 15:12:44.633306 2026] [security2:error] [pid 30583:tid 30583] [client 149.22.87.41:33585] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.heartshapedboy.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.heartshapedboy.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akAgrMnS4_k6scnhwXP5fwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 18:50:26
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 14:50:19.877837 2026] [security2:error] [pid 1097:tid 1097] [client 149.22.87.41:28523] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kraftrentals.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kraftrentals.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akAba_74bRXcxJ4Xz50T4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 18:03:16
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 14:03:10.053886 2026] [security2:error] [pid 27256:tid 27256] [client 149.22.87.41:28127] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||backstore.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backstore.com"] [uri "/backstore/Index_Products.htm/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akAQXkdHz--PHaNEwbDm6AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 03:04:21
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 23:04:18.176863 2026] [security2:error] [pid 22358:tid 22358] [client 149.22.87.41:45193] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bowdens-landing.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bowdens-landing.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj89sq90T_-sd3oBxMYzaQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 02:33:58
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 22:33:52.582355 2026] [security2:error] [pid 9379:tid 9379] [client 149.22.87.41:49623] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.salernospizza.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.salernospizza.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj82kINgjvSQFn1pJZ8D1AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 02:04:27
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 22:04:23.071492 2026] [security2:error] [pid 17099:tid 17099] [client 149.22.87.41:62399] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.laboquimia.es|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.laboquimia.es"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj8vpy5LJ9z8AujqMows4AAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 01:19:23
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 21:19:19.405584 2026] [security2:error] [pid 23987:tid 23987] [client 149.22.87.41:40699] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aabondwnc.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aabondwnc.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj8lF51RUseyKZDxFCAHmAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 23:44:24
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 19:44:20.459386 2026] [security2:error] [pid 29592:tid 29592] [client 149.22.87.41:58095] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.willandtrustlaw.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.willandtrustlaw.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj8O1E2sbMoixd8F7vQ22gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 17:01:28
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 13:01:22.778639 2026] [security2:error] [pid 9269:tid 9269] [client 149.22.87.41:29373] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rimworld.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rimworld.com"] [uri "/notra/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj1e4pP2cl54a-5K5qE15gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 21:36:37
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 17:36:32.339081 2026] [security2:error] [pid 1076:tid 1076] [client 149.22.87.41:25847] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ichoosethelight.org|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ichoosethelight.org"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "ajxN4IVWEh2b_QyRu3bzxAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 03:20:11
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.41 (unn-149-22-87-41.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 23:20:04.700146 2026] [security2:error] [pid 26999:tid 26999] [client 149.22.87.41:49893] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.havilahmalone.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.havilahmalone.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "ajtM5POsqKVxgni3Jwd2DwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack