๐บ๐ธ
TPI-Abuse
2025-12-25 16:51:25
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 11:51:22.183582 2025] [security2:error] [pid 9070:tid 9070] [client 149.28.33.250:52740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.californiaappraisers.net|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.californiaappraisers.net"] [uri "/2021.backup"] [unique_id "aU1rin-AGO14vsEF1fvzWgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-25 12:08:38
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 07:08:32.033909 2025] [security2:error] [pid 19334:tid 19334] [client 149.28.33.250:39592] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cyberrob.net|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cyberrob.net"] [uri "/2021.backup"] [unique_id "aU0pQPkUQi_b7ytCKRP1rwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-25 05:03:17
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 00:03:13.893494 2025] [security2:error] [pid 4742:tid 4742] [client 149.28.33.250:59714] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||madrigalscripts.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "madrigalscripts.com"] [uri "/2021.backup"] [unique_id "aUzFkUpblOV868CzCRXUbwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-23 23:56:21
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 23 18:56:13.747136 2025] [security2:error] [pid 32759:tid 32759] [client 149.28.33.250:56402] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||secureonebank.net|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "secureonebank.net"] [uri "/2021.backup"] [unique_id "aUssHaIMQS6AuPn_z038UwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-22 23:47:52
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 22 18:47:45.171037 2025] [security2:error] [pid 31164:tid 31164] [client 149.28.33.250:46430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dmasoftlab.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dmasoftlab.com"] [uri "/dmasoftlabcom.backup"] [unique_id "aUnYoRwyYNhY10fncN30kgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-22 12:50:27
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 22 07:50:23.800254 2025] [security2:error] [pid 26928:tid 26928] [client 149.28.33.250:59796] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||forma.crep-psych.org|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "forma.crep-psych.org"] [uri "/forma.backup"] [unique_id "aUk-j3uROiCnCWDkdH62oAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2025-12-21 19:47:15
(7 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing. Ip 149.28.33.250 performed ' ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/http-probing. Ip 149.28.33.250 performed 'crowdsecurity/http-probing' (11 events over 9.746822476s) at 2025-12-21 19:47:13.999424536 +0000 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-20 00:48:58
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 149.28.33.250 (149.28.33.250.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 19:48:50.290138 2025] [security2:error] [pid 31669:tid 31669] [client 149.28.33.250:52354] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.mastersonsmotel.ca|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.mastersonsmotel.ca"] [uri "/site.backup"] [unique_id "aUXycoQMJrTr2xIwY0hugwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
mbtweb
2025-10-25 10:21:00
(9 months ago)
Report black hash triggering via Imuniy360
Brute-Force
Exploited Host
Web App Attack