Anonymous
2026-07-13 13:54:03
(1 month ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2026-07-13 13:50:02
(1 month ago)
suspicious request in access.log
Web App Attack
🇯🇵
SentinalX by uzumaru
2026-07-04 06:39:10
(1 month ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: cloudflare.com:443
show less
Open Proxy
Port Scan
🇺🇸
TPI-Abuse
2026-07-03 22:24:49
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 18:24:46.964671 2026] [security2:error] [pid 27371:tid 27371] [client 155.2.216.29:31081] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||primestatepainting.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "primestatepainting.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akg2rk9zRqsYLgnXWJkXtgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 22:06:53
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 18:06:49.331376 2026] [security2:error] [pid 14988:tid 14988] [client 155.2.216.29:25359] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zezel.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zezel.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgyeeWCQHxyJyjz0zTrkwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 21:47:21
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 17:47:14.836260 2026] [security2:error] [pid 18202:tid 18202] [client 155.2.216.29:55911] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||domainexecs.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "domainexecs.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgt4nbY8N90NG_VVwmPzQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 21:21:59
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 17:21:54.382408 2026] [security2:error] [pid 31806:tid 31806] [client 155.2.216.29:41307] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||idetailingcreatives.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "idetailingcreatives.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgn8miSMeWEjmdNeTpOsQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 21:03:57
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 17:03:50.362835 2026] [security2:error] [pid 4126:tid 4126] [client 155.2.216.29:32153] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||compliancedepts.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "compliancedepts.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgjth7x548EzSG2BqndOQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 20:44:09
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 16:44:02.736638 2026] [security2:error] [pid 14590:tid 14590] [client 155.2.216.29:20725] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||corstratinc.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "corstratinc.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgfEiiikvDaexZjg_qO2gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 20:22:52
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 16:22:48.351269 2026] [security2:error] [pid 2612:tid 2612] [client 155.2.216.29:33797] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holesandcorners.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holesandcorners.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgaGBQYttB_Ubj9f5NyCwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 20:03:56
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 16:03:53.207899 2026] [security2:error] [pid 27007:tid 27007] [client 155.2.216.29:39885] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||restlesseye.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "restlesseye.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgVqYvTJ-lCcrV2m88jOQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 19:47:35
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 15:47:32.442041 2026] [security2:error] [pid 11084:tid 11084] [client 155.2.216.29:47845] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||revision.ws|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "revision.ws"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgR1P6UvsCvjg50CYVy3gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 19:27:52
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 15:27:48.365305 2026] [security2:error] [pid 16172:tid 16172] [client 155.2.216.29:34307] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "five96.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgNNLuRbe32nMzavzKTdAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 19:11:20
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 15:11:16.412569 2026] [security2:error] [pid 4170:tid 4170] [client 155.2.216.29:48925] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||realtorpaul.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "realtorpaul.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgJVP59BdM1MPxTscTFaAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 18:51:25
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 14:51:20.352345 2026] [security2:error] [pid 25593:tid 25593] [client 155.2.216.29:32567] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||miraclepunchy.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "miraclepunchy.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgEqMADK5olog46o6rJ_AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack