๐บ๐ธ
TPI-Abuse
2026-09-16 10:00:31
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:00:27.000139 2026] [security2:error] [pid 16413:tid 16421] [client 182.92.79.39:38960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ardentsi.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ardentsi.com"] [uri "/okok.cer"] [unique_id "aqpoulmGDa2B2f4yDL7H3AAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 09:31:34
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:31:28.958636 2026] [security2:error] [pid 20490:tid 20490] [client 182.92.79.39:59392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||architx.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "architx.com"] [uri "/okok.cer"] [unique_id "aqph8PAIPX3rwPubsTQ7SgAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 07:05:38
(5 hours ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (440/60 min)'; Requests=440
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-15 14:14:17
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:14:11.684656 2026] [security2:error] [pid 759:tid 897] [client 182.92.79.39:46604] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||andestravel.net|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "andestravel.net"] [uri "/okok.cer"] [unique_id "aqlSs5_4cRd5IdJfy2WiuQAAApI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 04:35:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:35:34.412561 2026] [security2:error] [pid 13768:tid 13768] [client 182.92.79.39:43236] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alrightletsgo.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alrightletsgo.com"] [uri "/okok.cer"] [unique_id "aqjLFuw1GAYM5qpdGgB1WwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 12:26:11
(1 day ago)
Bot / seems abusive / Apache connections: 122
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 04:16:16
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 182.92.79.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 00:16:09.118940 2026] [security2:error] [pid 14230:tid 14230] [client 182.92.79.39:55258] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||albertmassaad.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "albertmassaad.com"] [uri "/okok.cer"] [unique_id "aqd1CcmaEScxB25Tj3iHPgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-07 18:03:35
(1 week ago)
scans/SQL injection/spam posts : 22 queries
Web App Attack
SQL Injection
๐ซ๐ท
tecnoacquisti.com
2026-09-05 19:35:28
(1 week ago)
PrestaShop Security Module: suspicious probe path detected (/admin/)
Web App Attack
๐บ๐ธ
SX Communications
2026-09-05 15:25:35
(1 week ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 182.92.79.39: traffic from this add ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 182.92.79.39: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐บ๐ธ
rdpguard.com
2026-09-05 07:02:28
(1 week ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-09-05 03:11:13
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ง๐ท
Peregrine
2026-09-02 19:05:47
(1 week ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 182.92.79.39 104.22.17.227 - - [29/Aug/2026:21:32:25 -030 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 182.92.79.39 104.22.17.227 - - [29/Aug/2026:21:32:25 -0300] "GET /static/warn/close.php HTTP/1.1" 404 414
show less
Bad Web Bot
๐ง๐ท
Peregrine
2026-09-01 03:10:09
(2 weeks ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 182.92.79.39 104.22.17.227 - - [29/Aug/2026:21:32:25 -030 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 182.92.79.39 104.22.17.227 - - [29/Aug/2026:21:32:25 -0300] "GET /static/warn/close.php HTTP/1.1" 404 414
show less
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2026-08-31 17:12:41
(2 weeks ago)
182.92.79.39 - - [31/Aug/2026:18:12:50 +0100] "GET /static/warn/close.php HTTP/1.1" 404 6446 "https: ...
show more
182.92.79.39 - - [31/Aug/2026:18:12:50 +0100] "GET /static/warn/close.php HTTP/1.1" 404 6446 "https://trailrides-wales.com/static/warn/close.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
182.92.79.39 - - [31/Aug/2026:18:12:50 +0100] "GET /include/ckeditor/plugins/smiley/images/angel_smile.gif HTTP/1.1" 404 6446 "https://trailrides-wales.com/include/ckeditor/plugins/smiley/images/angel_smile.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
182.92.79.39 - - [31/Aug/2026:18:12:51 +0100] "GET /zb_users/emotion/face/Music.gif HTTP/1.1" 404 6446 "https://trailrides-wales.com/zb_users/emotion/face/Music.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack