๐บ๐ธ
TPI-Abuse
2026-06-08 00:10:33
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 20:10:00.422521 2026] [security2:error] [pid 512:tid 512] [client 194.110.150.117:49783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.csm-dtc.com"] [uri "/wp-config.php.2"] [unique_id "aiYIWIdGJRoR4i9m9Ny6LQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 10:17:07
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 06:16:44.897620 2026] [security2:error] [pid 8341:tid 8341] [client 194.110.150.117:20293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evolute.io"] [uri "/wp-config.php.2"] [unique_id "aiFQjF7Ti0jt4s9_HwFZqQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-06 11:47:58
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-47.194.110.150.117.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-47.194.110.150.117.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-06 08:42:24
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 11-42.194.110.150.117.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 11-42.194.110.150.117.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 02:16:36
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 22:16:32.032446 2026] [security2:error] [pid 2294072:tid 2294072] [client 194.110.150.117:64355] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Danbury II/Stetson Coffee/Thumbs.db"] [unique_id "aeBGgFECYE-fonQIxHQtZwAAAAw"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Danbury%20II/Stetson%20Coffee/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 01:57:14
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 21:57:08.335333 2026] [security2:error] [pid 3790673:tid 3790673] [client 194.110.150.117:63823] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||artisticheadstones.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "artisticheadstones.com"] [uri "/"] [unique_id "aeBB9IU4eZqzpmhH-6_J3AAAAAU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 17:06:05
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 194.110.150.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 12:06:00.169577 2026] [security2:error] [pid 14676:tid 14676] [client 194.110.150.117:42929] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||advancedmotorsports.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "advancedmotorsports.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZ3aeL7W4vaNXHPKoiMDOgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-01-12 08:20:09
(5 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ฉ๐ช
HandyTreff.de
2025-12-01 06:25:55
(6 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -23.778 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -23.778 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.4106.7
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-06-25 14:20:06
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐จ๐ฆ
wil.com
2024-09-26 05:26:42
(1 year ago)
GlobalProtect login attempts with user fkent.
VPN IP
Brute-Force
๐บ๐ธ
cory rabalais
2023-05-26 16:27:34
(3 years ago)
credential stuffing and password spraying
Brute-Force
๐บ๐ธ
cory rabalais
2023-05-26 16:27:34
(3 years ago)
credential stuffing and password spraying
Brute-Force
๐บ๐ธ
WhiteFireOCN1
2023-05-23 20:22:54
(3 years ago)
Targeted credential stuffing attack, observed 2023-05-23T06:18:25. Part of an attack that included 1 ...
show more
Targeted credential stuffing attack, observed 2023-05-23T06:18:25. Part of an attack that included 130 logins from 121 IPs. Likely being used as a proxy/tor exit node.
show less
Hacking
Brute-Force
Exploited Host
๐ฟ๐ฆ
IrisFlower
2022-01-13 23:03:37
(4 years ago)
Unauthorized connection attempt detected from IP address 194.110.150.117 to port 443 [J]
Port Scan
Hacking