π©πͺ
LRob
2026-10-06 04:40:46
(4 days ago)
Secret file probe | method: GET | path: /.git/HEAD | ua: Mozilla/5.0 (X11; Linux x86_64; rv:153.0) G ...
show more
Secret file probe | method: GET | path: /.git/HEAD | ua: Mozilla/5.0 (X11; Linux x86_64; rv:153.0) Gecko/20100101 Firefox/153.0
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-03 12:47:43
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 08:47:38.953829 2026] [security2:error] [pid 28153:tid 28153] [client 191.102.132.5:43813] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "asD5anFdiM4WT80kr3C1CgAAAA8"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 08:48:55
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:48:46.267537 2026] [security2:error] [pid 19798:tid 19949] [client 191.102.132.5:63593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwainet.com"] [uri "/.env"] [unique_id "aqupbtYvbzONyL5caX7QLQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 11:41:43
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 07:41:35.409104 2026] [security2:error] [pid 24621:tid 24621] [client 191.102.132.5:35443] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aqfdb3KSwyqEkQPTVm38MQAAAAc"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 15:17:10
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:17:02.262010 2026] [security2:error] [pid 11969:tid 11969] [client 191.102.132.5:27879] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apg97ow6RLTtkRRkpD8fGwAAAAA"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 09:26:49
(2 months ago)
FortiWeb WAF: 24 attacks detected. Threat Score: 11452555. Types: Client Management(12), Signature D ...
show more
FortiWeb WAF: 24 attacks detected. Threat Score: 11452555. Types: Client Management(12), Signature Detection(12). Origin: United States.
show less
Web App Attack
π¦πΊ
MAGIC
2026-05-23 01:07:53
(4 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π¨π
backslash
2026-05-10 07:15:02
(5 months ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-03 21:32:15
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 17:32:09.684156 2026] [security2:error] [pid 7302:tid 7302] [client 191.102.132.5:65515] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.fundingworkingcapital.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.fundingworkingcapital.com"] [uri "/mailto:[email protected] "] [unique_id "afe-2V_N0XlkDswYhMko4QAAAAM"], referer: http://www.fundingworkingcapital.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-03-17 23:53:50
(6 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 01-53.191.102.132.5.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 01-53.191.102.132.5.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
πΊπΈ
rsa
2026-03-13 16:05:00
(6 months ago)
excessive crawling
DDoS Attack
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-16 09:36:16
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 04:36:12.482894 2026] [security2:error] [pid 9137:tid 9137] [client 191.102.132.5:36185] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZLlDHe8kGR7kg7W_6wSkQAAAB8"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-07 05:19:48
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
π±π»
garmtech.com
2026-01-14 06:44:13
(8 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-44.191.102.132.5.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-44.191.102.132.5.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
π¦πΊ
MAGIC
2026-01-08 01:13:16
(9 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot