๐บ๐ธ
TPI-Abuse
2026-08-20 05:23:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 01:23:13.595533 2026] [security2:error] [pid 18211:tid 18211] [client 191.102.129.28:52787] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aoaPQVizBg_oTmQn4iYuLgAAABQ"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 00:36:15
(4 weeks ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 00:28:21
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 20:28:14.653993 2026] [security2:error] [pid 28153:tid 28153] [client 191.102.129.28:30131] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "aiYMnkC90Bk2YFCPstOxMgAAAGA"], referer: http://www.americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฎ
administrator
2026-06-02 22:08:47
(2 months ago)
2026-06-01 14:08:33,403 fail2ban.actions [1162]: NOTICE [apache-auth] Ban 191.102.129.28
202 ...
show more
2026-06-01 14:08:33,403 fail2ban.actions [1162]: NOTICE [apache-auth] Ban 191.102.129.28
2026-06-01 14:08:33,403 fail2ban.actions [1162]: NOTICE [apache-auth] Ban 191.102.129.28
2026-06-01 14:08:33,403 fail2ban.actions [1162]: NOTICE [apache-auth] Ban 191.102.129.28
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 01:57:00
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 21:56:54.881974 2026] [security2:error] [pid 12623:tid 12623] [client 191.102.129.28:48715] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "afarZm345QgieovAIzzuKgAAABg"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-15 15:11:25
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 18-11.191.102.129.28.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 18-11.191.102.129.28.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 23:02:29
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 19:02:25.355117 2026] [security2:error] [pid 27705:tid 27705] [client 191.102.129.28:29273] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "acHGgSyt5YXj9IjrCykAJwAAAAs"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-21 11:01:32
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:13-01.191.102.129.28
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 20:59:10
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 15:59:02.495777 2026] [security2:error] [pid 14497:tid 14497] [client 191.102.129.28:58669] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pharmaceuticalsalescertifications.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pharmaceuticalsalescertifications.com"] [uri "/mailto:[email protected] "] [unique_id "aZy_loI59A4-Rsu4SvmsAAAAAAU"], referer: http://www.pharmaceuticalsalescertifications.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-02-22 03:21:27
(5 months ago)
ban-reviewer auto report; ip=191.102.129.28; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=191.102.129.28; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'http:scan' scenario; Port Scan (category 14) detected in abuseipdb context; No evidence of legitimate activity or high-volume requests
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-02-12 09:59:08
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 04:59:01.475200 2026] [security2:error] [pid 9482:tid 9482] [client 191.102.129.28:48627] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aY2kZZ1vF2v7NuiiEufJmAAAABI"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2025-12-26 13:47:26
(7 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-03 12:44:27
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 03 08:44:23.255763 2025] [security2:error] [pid 1665598:tid 1665598] [client 191.102.129.28:40387] [client 191.102.129.28] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aBYPp9ElBKwsBs6LUwcFfgAAAAA"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-04-05 04:06:17
(1 year ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐ฎ๐ฉ
Burayot
2025-02-27 08:29:30
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 191.102.129.28 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 191.102.129.28 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack