Anonymous
2026-09-25 10:59:00
(1 week ago)
botnet
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
Hacking
๐ฉ๐ช
mkln.org
2026-09-18 08:16:23
(2 weeks ago)
Comment spam: 1 submissions to a WordPress comment form between 2026-09-18 and 2026-09-18 UTC, all c ...
show more
Comment spam: 1 submissions to a WordPress comment form between 2026-09-18 and 2026-09-18 UTC, all caught by a hidden honeypot field.
show less
Blog Spam
๐ซ๐ฎ
JimArchon72
2026-09-14 01:30:27
(3 weeks ago)
2026/09/14 01:28:48 "GET /phpmyadmin/ HTTP/1.1"
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-09 08:24:11
(4 weeks ago)
Auto-Ban [2026-09-09 08:24:11]: CRITICAL: bot trap (soft) | host=zatoca.com | route=/api/trap/intern ...
show more
Auto-Ban [2026-09-09 08:24:11]: CRITICAL: bot trap (soft) | host=zatoca.com | route=/api/trap/internal/reviews-sync | hits=1 | ua=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
show less
Hacking
Web App Attack
๐บ๐ธ
dtorrer
2026-09-09 01:25:25
(4 weeks ago)
Client attempted to submit spam on a website post.
Blog Spam
๐บ๐ธ
TPI-Abuse
2026-09-01 20:28:20
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:28:14.910611 2026] [security2:error] [pid 27334:tid 27334] [client 191.102.129.161:38741] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apc1XlvmRMThGsvOn3SAeQAAAC4"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:19:13
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:19:07.487740 2026] [security2:error] [pid 27621:tid 27621] [client 191.102.129.161:65303] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "apC32694xCjYfiaCyrkAfQAAAAE"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-08-11 15:06:48
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
Anonymous
2026-07-22 00:41:58
(2 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-05-17 23:40:06
(4 months ago)
Fail2Ban banned 191.102.129.161 for security violations in jail nginx-aggressive. Log: 2026/05/17 13 ...
show more
Fail2Ban banned 191.102.129.161 for security violations in jail nginx-aggressive. Log: 2026/05/17 13:46:11 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 191.102.129.161, server: [REDACTED]
2026/05/17 23:40:05 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 191.102.129.161, server: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2026-04-24 18:22:18
(5 months ago)
1777053624.507477 191.102.129.161 103.166.156.58 65535_2-4-8-1-3_1260_10 2026-04-25 01:00:24 WIB
...
Email Spam
Hacking
๐ฑ๐ป
garmtech.com
2026-04-24 05:38:54
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-38.191.102.129.161.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-38.191.102.129.161.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 10:09:28
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 06:09:20.619550 2026] [security2:error] [pid 1897913:tid 1897913] [client 191.102.129.161:36227] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aeSp0Oc1M4kiSqBErMTnVwAAAAQ"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 09:36:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 05:36:11.190330 2026] [security2:error] [pid 21635:tid 21635] [client 191.102.129.161:44011] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acehC212QOB0-Mj41yMvNwAAABQ"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-21 06:06:07
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 01:06:00.495783 2026] [security2:error] [pid 5903:tid 5903] [client 191.102.129.161:59939] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZlLSLQnM-I26VuLw3hVcQAAAAk"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack