๐บ๐ธ
TPI-Abuse
2026-06-09 04:54:00
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:53:54.723935 2026] [security2:error] [pid 31345:tid 31345] [client 191.102.129.153:42239] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aiecYjh3r0fiepjbQwEIXwAAAAU"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
VeteranOwnedBusiness.com
2026-04-25 14:01:00
(1 month ago)
blog comment spam
Blog Spam
๐บ๐ธ
TPI-Abuse
2026-04-14 09:44:47
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 05:44:40.834911 2026] [security2:error] [pid 3972269:tid 3972269] [client 191.102.129.153:30999] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "ad4MiILjpx1T-hs8kRSdegAAACQ"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-03 10:35:00
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-34.191.102.129.153.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-34.191.102.129.153.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ซ๐ท
tilellit.pro
2026-02-11 15:29:08
(4 months ago)
Fail2Ban banned 191.102.129.153 for security violations in jail nginx-aggressive. Log: 2026/02/11 15 ...
show more
Fail2Ban banned 191.102.129.153 for security violations in jail nginx-aggressive. Log: 2026/02/11 15:29:04 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 191.102.129.153, server: [REDACTED]
2026/02/11 15:29:07 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 191.102.129.153, server: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-02-07 05:46:03
(4 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-10 07:56:46
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 10 02:56:39.644914 2026] [security2:error] [pid 31852:tid 31852] [client 191.102.129.153:26039] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aWIGNzHx-okHBpP8FrbYfAAAAAc"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Globe2
2026-01-05 07:01:34
(5 months ago)
ModSec - Multiple 403s within a short period of time [server: H3]
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2025-12-30 19:19:48
(5 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-12-29 05:57:49
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:57:44.362266 2025] [security2:error] [pid 27221:tid 27221] [client 191.102.129.153:53003] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.genevainvestors.com:80|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.genevainvestors.com"] [uri "/mailto:[email protected] "] [unique_id "aVIYWL170IZxezf57na9KQAAAAY"], referer: http://www.genevainvestors.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 18:50:45
(7 months ago)
(mod_security) mod_security (id:210740) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210740) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 13:50:37.541237 2025] [security2:error] [pid 4972:tid 4972] [client 191.102.129.153:32237] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.buffaloweddingdeejay.com:80|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.buffaloweddingdeejay.com"] [uri "/Buffalo_Wedding_Dee_Jay/Corey/DJ_Corey/DJ_Corey_Entertainment_and_Divas_Consulting_&_Travel_(716)_833-1981.html"] [unique_id "aRjLfcjL1b11qPnagOm4_gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 09:54:45
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 05:54:40.331702 2025] [security2:error] [pid 4285:tid 4285] [client 191.102.129.153:44707] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vangentholding.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vangentholding.com"] [uri "/mailto:[email protected] "] [unique_id "aMFK4GYxvyAfb0L96YE2GQAAABA"], referer: https://www.vangentholding.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-15 03:09:49
(1 year ago)
Malicious activity detected
Hacking
Web App Attack