๐บ๐ธ
TPI-Abuse
2025-11-26 17:25:59
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 12:25:52.683853 2025] [security2:error] [pid 16108:tid 16108] [client 191.96.146.167:47853] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kwtlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kwtlaw.com"] [uri "/old/mysql.sql"] [unique_id "aSc4IH2PireojpOLPiGwygAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:01:40
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:01:36.389105 2025] [security2:error] [pid 9377:tid 9377] [client 191.96.146.167:35085] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.crypto-stamps.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.crypto-stamps.com"] [uri "/restore/www.sql"] [unique_id "aSP0wEDtv0gWADQaSyO0ugAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2025-11-21 00:06:05
(9 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-20 03:21:18
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 22:21:09.947419 2025] [security2:error] [pid 19627:tid 19627] [client 191.96.146.167:60773] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pellman-world.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pellman-world.com"] [uri "/old/mysql.sql"] [unique_id "aR6JJUk_0Q8ohelRuDzIxwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2025-11-10 20:16:57
(10 months ago)
/backups/credentials.txt
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 02:08:05
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 09 21:07:58.736395 2025] [security2:error] [pid 17381:tid 17381] [client 191.96.146.167:41215] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dudleyanddudley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dudleyanddudley.com"] [uri "/mysql.sql"] [unique_id "aRFI_pk9L38KQovdI0mjTQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2025-11-07 21:33:27
(10 months ago)
Web vulnerability scanning
Web Spam
Brute-Force
Web App Attack
๐ฏ๐ต
Valhalla
2025-11-06 01:18:29
(10 months ago)
/backups/website.gz
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-02 09:29:15
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 02 04:29:10.443834 2025] [security2:error] [pid 7513:tid 7528] [client 191.96.146.167:23409] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nobletitles.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nobletitles.org"] [uri "/backup/backup.sql"] [unique_id "aQckZgmfyYLplH_WyNDICgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2025-10-28 22:29:58
(10 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-10-28 06:49:03
(10 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
Thaliruth
2025-10-25 05:21:39
(10 months ago)
191.96.146.167 - - [25/Oct/2025:07:21:38 +0200] "HEAD /backups/backup.sql.zip HTTP/1.0" 404 3776 "-" ...
show more
191.96.146.167 - - [25/Oct/2025:07:21:38 +0200] "HEAD /backups/backup.sql.zip HTTP/1.0" 404 3776 "-" "-"
...
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-10-25 03:39:23
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 23:39:16.261634 2025] [security2:error] [pid 9017:tid 9017] [client 191.96.146.167:47301] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||oliverhardy.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oliverhardy.com"] [uri "/bak/mysql.sql"] [unique_id "aPxGZBHOlwQ_f1ovHyUlRgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack