๐ณ๐ฑ
Alt255
2026-10-05 08:52:21
(1 day ago)
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 191.102.129.165 - - [05/Oct/2026:10:52:13 +0200] "GET /.git/HEAD HTTP/1.1" 404 2898 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:153.0) Gecko/20100101 Firefox/153.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 22:36:56
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:36:51.862908 2026] [security2:error] [pid 21310:tid 21310] [client 191.102.129.165:63259] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aqclgy2lqzPtF8Jjc7qwEAAAAAI"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 21:51:42
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:51:37.558006 2026] [security2:error] [pid 32454:tid 32454] [client 191.102.129.165:30741] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apnr6Qa3NeJzmzv3xGVS2gAAAAo"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 11:34:03
(2 months ago)
FortiWeb WAF: 28 attacks detected. Threat Score: 10564330. Types: Client Management(14), Signature D ...
show more
FortiWeb WAF: 28 attacks detected. Threat Score: 10564330. Types: Client Management(14), Signature Detection(14). Origin: United States.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-19 03:38:48
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:06-38.191.102.129.165
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-18 18:42:21
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-42.191.102.129.165.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-42.191.102.129.165.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-19 16:06:16
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-06.191.102.129.165.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-06.191.102.129.165.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-09 18:44:34
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-44.191.102.129.165.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-44.191.102.129.165.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-26 07:52:26
(6 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 09-52.191.102.129.165.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 09-52.191.102.129.165.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฆ๐บ
MAGIC
2026-03-14 00:09:36
(6 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-25 10:16:23
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 05:16:18.256285 2026] [security2:error] [pid 3533:tid 3533] [client 191.102.129.165:35647] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aZ7L8iZ4F8DJJufwjpfFbgAAAAw"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-02-20 09:27:02
(7 months ago)
SQL Injection
๐ฆ๐บ
MAGIC
2026-02-10 01:01:17
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฉ๐ช
SCHAPPY
2026-02-03 14:42:41
(8 months ago)
Critical web app attack detected. Illegal Accept header: charset parameter
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-09 00:44:38
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 08 19:44:30.931060 2026] [security2:error] [pid 23470:tid 23470] [client 191.102.129.165:63755] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aWBPbrT2O_2NLTeAnGO3pQAAAAw"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack