🇺🇸
TPI-Abuse
2026-09-22 04:57:33
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 181.94.224.134 (host-181-94-224-134.personal.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 181.94.224.134 (host-181-94-224-134.personal.net.py): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:57:27.789686 2026] [security2:error] [pid 5590:tid 5590] [client 181.94.224.134:59022] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tpdtuberental.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tpdtuberental.com"] [uri "/"] [unique_id "arIKtyjhx903e989fhzhYwAAACk"], referer: https://mcdermaidfam.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-11 09:21:00
(2 weeks ago)
block ruleset A5EE6C8F745F0934168261886A3817E5C386412A
Bad Web Bot
🇺🇸
gui-ying233
2026-08-25 12:27:47
(1 month ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
🇩🇪
klaus_ph
2026-08-16 13:08:06
(1 month ago)
181.94.224.134 - - [15/Aug/2026:05:06:07 +0200] "GET /lka/Record/c0287204/Description?lng=de HTTP/1. ...
show more
181.94.224.134 - - [15/Aug/2026:05:06:07 +0200] "GET /lka/Record/c0287204/Description?lng=de HTTP/1.1" 500 24112 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.60 Safari/537.36"
...
show less
Bad Web Bot
🇺🇸
kosada.com
2026-08-09 11:35:25
(1 month ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-30 11:35:22
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 181.94.224.134 (host-134.181-94-224.personal.ne ...
show more
(mod_security) mod_security (id:210730) triggered by 181.94.224.134 (host-134.181-94-224.personal.net.py): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 07:35:06.666536 2026] [security2:error] [pid 1691002:tid 1691002] [client 181.94.224.134:2880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pswebsite.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pswebsite.com"] [uri "/youtube.com"] [unique_id "ams26v1fC5WxFZqzM0lnYwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-29 21:12:01
(4 months ago)
Unauthorized connection attempt on Port 2323
Port Scan
Hacking
Exploited Host
🇮🇹
VHosting
2025-12-22 21:09:45
(9 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
🇺🇸
TPI-Abuse
2025-12-10 14:52:11
(9 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
Anonymous
2025-12-06 11:25:29
(9 months ago)
botnet
DDoS Attack
Anonymous
2025-11-25 11:46:59
(10 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-18 03:23:42
(10 months ago)
scanning http requests from known botnet
Web App Attack
🇮🇩
hermawan
2025-10-15 12:58:16
(11 months ago)
[Wed Oct 15 19:35:07.241528 2025] [security2:error] [pid 714767:tid 140019331221184] [client 181.94. ...
show more
[Wed Oct 15 19:35:07.241528 2025] [security2:error] [pid 714767:tid 140019331221184] [client 181.94.224.134:59599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "WOW64" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "228"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: WOW64 found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.4000.0 Iron Safari/537.36 request_line = GET /index.php/prakiraan-musim/4198-prakiraan-musim-hujan/prakiraan-puncak-musim-hujan/prakiraan-6-bulanan-prakiraan-puncak-musim-hujan-tahun-2023-2024-zona-musim-di-provinsi-jawa-timur/555560362-prakiraan-6-bulanan-prakiraan-puncak-musim-hujan-tahun-2023-2024-zona-musim-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-musim/4198-prakiraan-musim-hujan/prakiraan
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2025-09-10 23:13:36
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 181.94.224.134 (host-134.181-94-224.personal.ne ...
show more
(mod_security) mod_security (id:210730) triggered by 181.94.224.134 (host-134.181-94-224.personal.net.py): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 19:13:28.611075 2025] [security2:error] [pid 2483:tid 2483] [client 181.94.224.134:21819] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aaabft.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aaabft.com"] [uri "/[email protected] "] [unique_id "aMIGGFsf0C7Li9GeJUsEMAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
exxos
2025-08-22 08:03:01
(1 year ago)
Attacks with Bad user agents
Hacking