🇺🇸
TPI-Abuse
2026-09-07 04:12:18
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.72 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:12:10.979475 2026] [security2:error] [pid 11910:tid 11910] [client 191.102.129.72:48415] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.clcmillvale.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.clcmillvale.com"] [uri "/mailto:[email protected] "] [unique_id "ap45moWiJ6naOaUA851zIgAAAAc"], referer: https://www.clcmillvale.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 21:02:48
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.72 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:02:42.932538 2026] [security2:error] [pid 11091:tid 11091] [client 191.102.129.72:35531] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apc9chDw-ObkJqMrGSF9kwAAABc"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 01:31:23
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.72 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:31:19.267528 2026] [security2:error] [pid 29733:tid 29733] [client 191.102.129.72:33145] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||constructionloansfunding.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "constructionloansfunding.com"] [uri "/mailto:[email protected] "] [unique_id "apDk555BB5zRtFQ1RuIS0wAAAAg"], referer: http://constructionloansfunding.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
neron
2026-08-06 06:29:43
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
Anonymous
2026-08-04 09:51:24
(1 month ago)
FortiWeb WAF: 24 attacks detected. Threat Score: 11328555. Types: Client Management(12), Signature D ...
show more
FortiWeb WAF: 24 attacks detected. Threat Score: 11328555. Types: Client Management(12), Signature Detection(12). Origin: United States.
show less
Web App Attack
Anonymous
2026-07-22 00:30:11
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-06 03:50:38
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.129.72 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.129.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 23:50:32.223156 2026] [security2:error] [pid 8781:tid 8781] [client 191.102.129.72:40131] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aksmCKgO0KaryZHhDa_UswAAABk"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-06-17 00:32:31
(2 months ago)
Cloudflare WAF: Request Path: /register2.html Request Query: Host: foro.elhacker.net userAgent: Moz ...
show more
Cloudflare WAF: Request Path: /register2.html Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Action: managed_challenge Source: firewallCustom ASN Description: WhiteLabelColo Country: US Method: POST Timestamp: 2026-06-17T00:32:31Z ruleId: 5012d84c6d9f467499149a3cd38d0b9d. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
🇪🇸
el-brujo
2026-06-15 10:29:17
(2 months ago)
Cloudflare WAF: Request Path: /register2.html Request Query: Host: foro.elhacker.net userAgent: Moz ...
show more
Cloudflare WAF: Request Path: /register2.html Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0 Action: managed_challenge Source: firewallCustom ASN Description: WhiteLabelColo Country: US Method: POST Timestamp: 2026-06-15T10:29:17Z ruleId: 5012d84c6d9f467499149a3cd38d0b9d. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
🇪🇸
el-brujo
2026-06-14 13:42:04
(2 months ago)
Cloudflare WAF: Request Path: /register2.html Request Query: Host: foro.elhacker.net userAgent: Moz ...
show more
Cloudflare WAF: Request Path: /register2.html Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Action: managed_challenge Source: firewallCustom ASN Description: WhiteLabelColo Country: US Method: POST Timestamp: 2026-06-14T13:42:04Z ruleId: 5012d84c6d9f467499149a3cd38d0b9d. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
🇪🇸
el-brujo
2026-06-14 06:28:48
(2 months ago)
Cloudflare WAF: Request Path: /register2.html Request Query: Host: foro.elhacker.net userAgent: Moz ...
show more
Cloudflare WAF: Request Path: /register2.html Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36 Action: managed_challenge Source: firewallCustom ASN Description: WhiteLabelColo Country: US Method: POST Timestamp: 2026-06-14T06:28:48Z ruleId: 5012d84c6d9f467499149a3cd38d0b9d. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
🇱🇻
garmtech.com
2026-06-13 14:23:41
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 17-23.191.102.129.72.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 17-23.191.102.129.72.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇱🇻
garmtech.com
2026-06-12 10:43:52
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-43.191.102.129.72.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-43.191.102.129.72.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇱🇻
garmtech.com
2026-06-12 09:32:44
(2 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:/ru/component/users/
Web App Attack
🇱🇻
garmtech.com
2026-06-12 09:32:44
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 12-32.191.102.129.72.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 12-32.191.102.129.72.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack