🇺🇸
TPI-Abuse
2026-03-16 17:48:49
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 13:48:41.127299 2026] [security2:error] [pid 6861:tid 6861] [client 191.96.146.167:35057] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brazilianbikinis.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brazilianbikinis.com"] [uri "/backup/wallet.dat"] [unique_id "abhCeequnoGGLRaU2veJVQAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-16 17:16:08
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 13:16:01.600786 2026] [security2:error] [pid 21067:tid 21067] [client 191.96.146.167:40173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ibeautyexchange.com"] [uri "/old/sftp-config.json"] [unique_id "abg60e2PECQSAhs0jaE0dQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-16 06:38:43
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 02:38:37.459770 2026] [security2:error] [pid 20307:tid 20386] [client 191.96.146.167:52097] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||siestakeybch.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "siestakeybch.com"] [uri "/backups/dump.sql"] [unique_id "abelbVHgLXROkmqWRdbt2AAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-15 10:01:45
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 06:01:40.708571 2026] [security2:error] [pid 4923:tid 4923] [client 191.96.146.167:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eddysgroup.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eddysgroup.com"] [uri "/backups/wallet.dat"] [unique_id "abaDhH8nOezQK0oIABa1TgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-15 04:43:18
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 00:43:13.427523 2026] [security2:error] [pid 6146:tid 6146] [client 191.96.146.167:53795] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||3dsportschannel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3dsportschannel.com"] [uri "/backup/mysql.sql"] [unique_id "abY44SZDK7JhVN2MrRJGLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-14 07:49:07
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 03:48:59.735305 2026] [security2:error] [pid 8038:tid 8038] [client 191.96.146.167:44829] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||matteozacchino.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "matteozacchino.dev"] [uri "/backup/www.sql"] [unique_id "abUS6_jtbGlC24LuaXRtiAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-03-14 01:30:45
(5 months ago)
1.068 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-11 21:54:43
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 17:54:38.196918 2026] [security2:error] [pid 931:tid 931] [client 191.96.146.167:30339] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||qualityelevatorcabs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "qualityelevatorcabs.com"] [uri "/backups/sql.sql"] [unique_id "abHknmdWc_TZDFfNFXU-wAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Penny Packer
2026-03-10 03:28:04
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
🇬🇧
consul.to
2026-02-23 06:32:46
(6 months ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
dynamix
2026-02-22 23:16:55
(6 months ago)
Multiple WAF Violations
Web App Attack
🇯🇵
VXG-NET
2026-02-12 01:10:34
(6 months ago)
port=80, indicator_type=info-leak
Hacking
🇺🇸
TPI-Abuse
2026-02-10 13:15:35
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 08:15:30.113422 2026] [security2:error] [pid 19685:tid 19685] [client 191.96.146.167:33797] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pcga.golf|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pcga.golf"] [uri "/old/dump.sql"] [unique_id "aYsvcoARGk0f80pkL5v6KQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-02-09 10:03:00
(6 months ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
Anytech
2026-02-09 10:01:41
(6 months ago)
CrowdSec detected: crowdsecurity/http-dos-swithcing-ua
Brute-Force
Web App Attack