๐บ๐ธ
TPI-Abuse
2026-08-24 17:01:23
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 13:01:18.770604 2026] [security2:error] [pid 31904:tid 31904] [client 185.94.32.156:51575] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Affinity II/Thumbs.db"] [unique_id "aox43ilD0fnO_bQlVChKYgAAAAg"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Affinity%20II/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 09:40:17
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 05:40:12.471616 2026] [security2:error] [pid 3153160:tid 3153160] [client 185.94.32.156:9475] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||muslera.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "muslera.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anrt_J4VyQOW4fxpVW4TgQAAABs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 22:10:00
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 18:09:56.176454 2026] [security2:error] [pid 23686:tid 23686] [client 185.94.32.156:16965] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Cozzia/pics/Thumbs.db"] [unique_id "akgzNJdCok1QYVGmyTIPdAAAABA"], referer: https://vitalitywebb.com/backstore/Cozzia/pics/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-07-02 15:33:00
(1 month ago)
IPBlock protected site ID [3192-af][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-05-18 15:27:00
(3 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-17 00:00:32
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 20:00:25.434488 2026] [security2:error] [pid 32537:tid 32537] [client 185.94.32.156:14497] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Ashton II Recliner/Ashton II Recliner/Havana Brown/Thumbs.db"] [unique_id "agkFGW6TFouKXLbuvTrM4AAAAAM"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Ashton%20II%20Recliner/Ashton%20II%20Recliner/Havana%20Brown/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-17 00:42:01
(4 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
Anonymous
2026-02-15 06:45:20
(6 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ธ๐ช
OnTheEdge
2025-11-28 17:04:08
(9 months ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-12 21:12:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.94.32.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 12 17:12:53.365952 2025] [security2:error] [pid 3245679:tid 3245679] [client 185.94.32.156:17881] [client 185.94.32.156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nekstlevel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nekstlevel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aCJkVbU-pGrk0m5tYQV-RwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-27 04:45:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐ฆ๐บ
oncord
2024-12-26 06:33:34
(1 year ago)
Form spam
Web Spam
Anonymous
2024-10-04 22:40:08
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
๐จ๐ฆ
wil.com
2024-09-25 01:05:31
(1 year ago)
GlobalProtect login attempts with user carmstrong.
VPN IP
Brute-Force