๐บ๐ธ
TPI-Abuse
2026-09-18 23:50:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 19:50:15.936928 2026] [security2:error] [pid 10948:tid 10948] [client 191.102.132.34:37989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brownweddingnapkins.com"] [uri "/.git/HEAD"] [unique_id "aq3ON1KtJeC7K4EYwdJlMQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-09-18 21:20:02
(4 days ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-09-18 17:11:48
(4 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-18 17:11 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-05 19:22:57
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:22:51.005436 2026] [security2:error] [pid 11200:tid 11200] [client 191.102.132.34:55735] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "apxsC-tEzCeXMmrbdWVjQwAAAAg"], referer: http://americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:58:09
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:58:02.663811 2026] [security2:error] [pid 30538:tid 30538] [client 191.102.132.34:33071] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apgdWu-2E-7YmA9neuRKZwAAABQ"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-24 00:33:44
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-33.191.102.132.34.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-33.191.102.132.34.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-18 12:05:39
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 15-05.191.102.132.34.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 15-05.191.102.132.34.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-18 07:51:22
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-51.191.102.132.34.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-51.191.102.132.34.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 18:52:13
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 14:52:07.789647 2026] [security2:error] [pid 14488:tid 14488] [client 191.102.132.34:43557] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||GarantaConsulting.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "garantaconsulting.com"] [uri "/mailto:[email protected] "] [unique_id "agi81x2WFMAwASm10r56TQAAACg"], referer: http://GarantaConsulting.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 07:06:13
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 03:06:07.571555 2026] [security2:error] [pid 1701151:tid 1701151] [client 191.102.132.34:61707] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aeR-33VEcP_nvOffD71z2AAAAAo"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 05:22:49
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 01:22:41.802191 2026] [security2:error] [pid 3905:tid 3905] [client 191.102.132.34:58207] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aci3ISb4LpY91FndHvxAHwAAAAE"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 18:25:51
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 14:25:46.985937 2026] [security2:error] [pid 24921:tid 24921] [client 191.102.132.34:37787] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "acA0KvIJa-Wkq4hDJX8i1QAAACI"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-18 00:41:26
(6 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-41.191.102.132.34.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-41.191.102.132.34.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-03-13 11:56:15
(6 months ago)
Fail2Ban banned 191.102.132.34 for security violations in jail nginx-aggressive. Log: 2026/03/13 11: ...
show more
Fail2Ban banned 191.102.132.34 for security violations in jail nginx-aggressive. Log: 2026/03/13 11:56:11 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 191.102.132.34, server: [REDACTED]
2026/03/13 11:56:14 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 191.102.132.34, server: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 15:12:13
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 10:12:06.527215 2026] [security2:error] [pid 20799:tid 20799] [client 191.102.132.34:64385] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZh5xtQlCqzD8bow4NFUsQAAAAs"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack