Anonymous
2026-02-18 10:03:35
(6 months ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: FR, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: FR, Attack patterns: WordPress scanning, Backup file probing
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-14 11:53:50
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 06:53:43.017724 2026] [security2:error] [pid 27101:tid 27101] [client 161.97.72.39:57578] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rogerheath.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rogerheath.com"] [uri "/wp-admin.bak"] [unique_id "aZBiR9C1EkeyAsYtEAkLyQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-14 07:11:37
(6 months ago)
wordpress-trap
Web App Attack
πΊπΈ
xmission.com
2026-02-13 23:43:01
(6 months ago)
161.97.72.39 - - [13/Feb/2026:16:43:00 -0700] "GET /dooce.com.zip HTTP/1.1" 404 8486 "-" "Mozilla/5. ...
show more
161.97.72.39 - - [13/Feb/2026:16:43:00 -0700] "GET /dooce.com.zip HTTP/1.1" 404 8486 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
161.97.72.39 - - [13/Feb/2026:16:43:00 -0700] "GET /www.dooce.com.zip HTTP/1.1" 404 8486 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
161.97.72.39 - - [13/Feb/2026:16:43:00 -0700] "GET /web.zip HTTP/1.1" 404 8486 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
π³π±
Savvii
2026-02-13 12:51:23
(6 months ago)
127 attempts against mh-pma-try-ban on draco
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 07:15:59
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 02:15:53.508138 2026] [security2:error] [pid 29415:tid 29415] [client 161.97.72.39:57378] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ieas.org|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ieas.org"] [uri "/bkp.bak"] [unique_id "aY7PqRwvxWHDXX3jV7vEnQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-12 09:07:38
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 04:07:32.712431 2026] [security2:error] [pid 1089375:tid 1089375] [client 161.97.72.39:35590] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||garon.us|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "garon.us"] [uri "/0.bak"] [unique_id "aY2YVLmX0KoEqsLzjxlszAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-02-12 05:43:27
(6 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-11 20:54:28
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 15:54:22.112193 2026] [security2:error] [pid 18991:tid 18991] [client 161.97.72.39:59336] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||digitalracemedia.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "digitalracemedia.com"] [uri "/2025.bak"] [unique_id "aYzsfuF1bfib6TCkDMcAuQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 10:55:52
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 05:55:46.023653 2026] [security2:error] [pid 14997:tid 14997] [client 161.97.72.39:36546] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||marjorierosenberg.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marjorierosenberg.com"] [uri "/php.bak"] [unique_id "aYm9Mjup4mmEeFZue7hwiQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-07 00:32:34
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 19:32:27.999532 2026] [security2:error] [pid 29806:tid 29806] [client 161.97.72.39:40388] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rotentendales.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rotentendales.com"] [uri "/home.bak"] [unique_id "aYaIGwtX051kh7Fn45Ck3wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-06 19:06:53
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 161.97.72.39 (vmi406040.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 14:06:50.014401 2026] [security2:error] [pid 9945:tid 9945] [client 161.97.72.39:50272] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brinkworthdungeon.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brinkworthdungeon.com"] [uri "/httpd.bak"] [unique_id "aYY7yuM8z8Kd0YWS_pPFUQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-02-03 23:44:12
(6 months ago)
10 attempts against mh-pma-try-ban on plum
Web App Attack
πΉπ·
rtbh.com.tr
2026-02-02 20:11:21
(6 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
πΉπ·
rtbh.com.tr
2026-02-01 20:11:20
(6 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force