๐บ๐ธ
TPI-Abuse
2026-07-19 10:04:42
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swi ...
show more
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swisscom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 06:04:36.712298 2026] [security2:error] [pid 26595:tid 26595] [client 178.199.76.208:51502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Umjkhvfhv.dat"] [unique_id "alyhNG-vmZJRZzOJcaWtwQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 03:27:04
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swi ...
show more
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swisscom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 23:26:58.320679 2026] [security2:error] [pid 30467:tid 30467] [client 178.199.76.208:52048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Xrsaumlpov.dll"] [unique_id "ajIUAnvIcyzUOjoK3esvagAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
podril1ak2.ru
2026-05-23 08:14:44
(2 months ago)
Blocked by UFW [80/tcp] | SPT: 44624 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefin ...
show more
Blocked by UFW [80/tcp] | SPT: 44624 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
podril1ak2.ru
2026-05-21 19:58:04
(2 months ago)
Blocked by UFW [80/tcp] | SPT: 33914 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefin ...
show more
Blocked by UFW [80/tcp] | SPT: 33914 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
podril1ak2.ru
2026-05-21 06:50:44
(2 months ago)
Blocked by UFW [80/tcp] | SPT: 35496 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefin ...
show more
Blocked by UFW [80/tcp] | SPT: 35496 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-20 23:32:22
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swi ...
show more
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swisscom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 19:32:16.104824 2026] [security2:error] [pid 15538:tid 15538] [client 178.199.76.208:57494] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Zqxmwhflnje.dll"] [unique_id "ag5EgK1QVBsHCxjYEWa8SAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 09:53:23
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swi ...
show more
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swisscom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 05:53:16.368788 2026] [security2:error] [pid 3718868:tid 3718868] [client 178.199.76.208:42924] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Umjkhvfhv.dat"] [unique_id "aensDMkz9qH4RfSwIAfW1wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-04-22 01:00:55
(3 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/178.199.76.208
2 ...
show more
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/178.199.76.208
2026-04-21 21:46:45 /02.08.2022.exe
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 21:37:08
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swi ...
show more
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swisscom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 17:37:00.483260 2026] [security2:error] [pid 15932:tid 15932] [client 178.199.76.208:45872] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Xrsaumlpov.dll"] [unique_id "acmbfAlZgCHuh5L0B8YkdgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 18:07:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swi ...
show more
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swisscom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 14:07:06.458643 2026] [security2:error] [pid 13919:tid 13919] [client 178.199.76.208:44116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Dxmnp.dll"] [unique_id "aa8MSjG0OV9C24Dmd-6RJQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-07 12:35:29
(5 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-25 00:40:01
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swi ...
show more
(mod_security) mod_security (id:210730) triggered by 178.199.76.208 (208.76.199.178.dynamic.cust.swisscom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 24 19:39:58.087330 2026] [security2:error] [pid 3934:tid 3934] [client 178.199.76.208:51148] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Vovaf.dat"] [unique_id "aXVmXkYy_PJeyMGsYNCONgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-01-23 00:59:49
(6 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/178.199.76.208
2 ...
show more
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/178.199.76.208
2026-01-22 04:06:47 /02.08.2022.exe
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-01-05 00:09:07
(6 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/178.199.76.208
2 ...
show more
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/178.199.76.208
2026-01-04 15:52:13 /02.08.2022.exe
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-12-30 00:30:52
(6 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/178.199.76.208
2 ...
show more
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/178.199.76.208
2025-12-29 06:06:07 /02.08.2022.exe
show less
Web App Attack