๐ต๐ฑ
Budyn
2026-10-04 09:17:28
(15 hours ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_12 | Action: AWS API Call | Token: akf ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_12 | Action: AWS API Call | Token: akf9s74n5eldbzbpzbzf5lt45 | Client Tool: aws-cli/2.33.12 md/awscrt#0.31.1 ua/2.1 os/linux#5.15.0-191-generic md/arch#x86_64 lang/python#3.13.11 md/pyimpl#CPython m/Z,E,g,b cfg/retry-mode#standard md...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 09:41:33
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:41:27.566091 2026] [security2:error] [pid 27887:tid 27887] [client 191.102.129.134:43563] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "danchujkoassoc.com"] [uri "/.git/HEAD"] [unique_id "arTwR-PG8BZMCN2GD60S9AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 16:14:18
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 12:14:11.450528 2026] [security2:error] [pid 17765:tid 17765] [client 191.102.129.134:33195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cedricwillems.be"] [uri "/.git/HEAD"] [unique_id "arAGUyfPpMPU29hD2EHsfQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 03:45:16
(2 weeks ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: HEAD | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: HEAD | path: /mailto:[email protected] | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 | 2026-09-20 03:45 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:04:27
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:04:21.213296 2026] [security2:error] [pid 31620:tid 31620] [client 191.102.129.134:57139] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aqlshQMIBDB4ZODKBhesvQAAAAw"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 20:11:18
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 16:11:13.158993 2026] [security2:error] [pid 5812:tid 5911] [client 191.102.129.134:28873] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ethicmark.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ethicmark.org"] [uri "/mailto:[email protected] "] [unique_id "an92YfrJ3sUEkcF_ntlc_wAAAJg"], referer: https://www.ethicmark.org
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 11:22:40
(2 months ago)
FortiWeb WAF: 14 attacks detected. Threat Score: 10687580. Types: Client Management(7), Signature De ...
show more
FortiWeb WAF: 14 attacks detected. Threat Score: 10687580. Types: Client Management(7), Signature Detection(7). Origin: United States.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 18:58:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 14:58:04.516288 2026] [security2:error] [pid 8833:tid 8833] [client 191.102.129.134:44315] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aiHKvMgfwnYHdx8sFR4PbwAAAEM"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-27 23:39:34
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-39.191.102.129.134.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-39.191.102.129.134.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐จ๐ญ
backslash
2026-05-10 07:12:00
(4 months ago)
Bad Web Bot
Anonymous
2026-04-24 11:44:00
(5 months ago)
botnet. scraping.
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
Hacking
๐ฎ๐ฉ
hermawan
2026-04-18 21:37:38
(5 months ago)
1776547863.594240 191.102.129.134 103.166.156.58 65535_2-4-8-1-3_1260_10 2026-04-19 04:31:03 WIB
...
Email Spam
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-31 14:45:07
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 10:44:55.343358 2026] [security2:error] [pid 14330:tid 14330] [client 191.102.129.134:40917] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acvd535jO6L9XwdvkHW33AAAABY"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-21 21:55:17
(6 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:23-55.191.102.129.134
Web App Attack
๐ช๐ธ
gnom4ik
2026-02-21 06:50:35
(7 months ago)
ban-reviewer auto report; ip=191.102.129.134; scenario=http:scan; verdict=valid_ban; confidence=0.85 ...
show more
ban-reviewer auto report; ip=191.102.129.134; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=scan/exploit pattern detected (http:scan); ip has active decisions total of 1; abuseipdb categories include port scan (14) and hacking (15)
show less
Port Scan
Hacking
Brute-Force