๐ธ๐ฎ
administrator
2026-08-05 22:04:18
(2 weeks ago)
2026-08-05 00:02:32,379 fail2ban.actions [1590202]: NOTICE [error-bots] Ban 191.102.129.140
...
show more
2026-08-05 00:02:32,379 fail2ban.actions [1590202]: NOTICE [error-bots] Ban 191.102.129.140
2026-08-05 00:02:32,379 fail2ban.actions [1590202]: NOTICE [error-bots] Ban 191.102.129.140
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-08-04 09:42:04
(2 weeks ago)
FortiWeb WAF: 14 attacks detected. Threat Score: 11377455. Types: Client Management(7), Signature De ...
show more
FortiWeb WAF: 14 attacks detected. Threat Score: 11377455. Types: Client Management(7), Signature Detection(7). Origin: United States.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-08-03 12:48:01
(2 weeks ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 15-48.191.102.129.140.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 15-48.191.102.129.140.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
Anonymous
2026-07-22 00:42:45
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ธ๐ฎ
administrator
2026-07-21 22:08:21
(1 month ago)
2026-07-20 13:33:26,553 fail2ban.actions [1132]: NOTICE [error-bots] Ban 191.102.129.140
202 ...
show more
2026-07-20 13:33:26,553 fail2ban.actions [1132]: NOTICE [error-bots] Ban 191.102.129.140
2026-07-20 13:33:26,553 fail2ban.actions [1132]: NOTICE [error-bots] Ban 191.102.129.140
2026-07-20 13:33:26,553 fail2ban.actions [1132]: NOTICE [error-bots] Ban 191.102.129.140
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-07 02:18:34
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 05-18.191.102.129.140.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 05-18.191.102.129.140.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 23:55:14
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 19:55:08.181076 2026] [security2:error] [pid 25826:tid 25826] [client 191.102.129.140:57111] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||constructionloansfunding.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "constructionloansfunding.com"] [uri "/mailto:[email protected] "] [unique_id "akb6XC8b73t0h7VQSlGVQwAAAA0"], referer: http://constructionloansfunding.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 08:00:00
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 03:59:53.166535 2026] [security2:error] [pid 20000:tid 20000] [client 191.102.129.140:55847] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.investorsfundingusa.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.investorsfundingusa.com"] [uri "/mailto:[email protected] "] [unique_id "ah_e-UZjAf-_Zug1yLLVQQAAAAk"], referer: http://www.investorsfundingusa.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-09 13:48:44
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-48.191.102.129.140.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-48.191.102.129.140.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2026-04-24 18:18:16
(3 months ago)
1777053597.417185 C1phWa4q8EPe598y9i 191.102.129.140 63319 103.166.156.58 80 1 HEAD staklim-jatim.bm ...
show more
1777053597.417185 C1phWa4q8EPe598y9i 191.102.129.140 63319 103.166.156.58 80 1 HEAD staklim-jatim.bmkg.go.id / http://staklim-jatim.bmkg.go.id - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 - 0 0 - - - - (empty) - - - - - - - - - he11nr050000_3658ef221638_000000000000_000000000000 04/25/2026-00:59:57.417185
...
show less
Email Spam
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-15 00:33:16
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 20:33:09.071911 2026] [security2:error] [pid 918219:tid 918219] [client 191.102.129.140:41267] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "ad7cxfpL__O3LBsPijSfQwAAABU"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-04 09:28:24
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 04:28:16.100459 2026] [security2:error] [pid 19968:tid 19968] [client 191.102.129.140:44983] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||oiseauxsisters.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "oiseauxsisters.com"] [uri "/our-story"] [unique_id "aaf7ML5Kgaq-tGIiOlSywgAAABU"], referer: https://oiseauxsisters.com/our-story
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 07:05:36
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 02:05:29.505727 2026] [security2:error] [pid 14103:tid 14103] [client 191.102.129.140:27113] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lockdownclaim.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lockdownclaim.com"] [uri "/mailto:[email protected] "] [unique_id "aaKTuYj3Vq1pd85AN8mZowAAAA0"], referer: http://lockdownclaim.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-20 15:34:39
(6 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 17-34.191.102.129.140.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 17-34.191.102.129.140.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 17:21:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 12:21:09.607855 2026] [security2:error] [pid 17418:tid 17418] [client 191.102.129.140:33993] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aYy6hTXxFsJX5VM0YMfmjAAAAAw"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack