๐บ๐ธ
TPI-Abuse
2026-10-08 10:32:05
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 211.149.133.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 211.149.133.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 06:31:59.509550 2026] [security2:error] [pid 9372:tid 9372] [client 211.149.133.225:39018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tell-me-first.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tell-me-first.com"] [uri "/okok.cer"] [unique_id "asdxH0W8tJlPCn34K54vDgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 00:30:29
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-07 03:47:09
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 18:25:46
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
LRob
2026-10-05 14:23:11
(6 days ago)
Web page flood (L7) | path: /1index.php, /cache.php, /xenon1337.php (+17 more)
DDoS Attack
Web App Attack
๐ช๐ธ
el-brujo
2026-10-04 05:32:11
(1 week ago)
211.149.133.225 - - [04/Oct/2026:07:32:09 +0200] "GET /apps/admin/view/default/layui/images/face/11. ...
show more
211.149.133.225 - - [04/Oct/2026:07:32:09 +0200] "GET /apps/admin/view/default/layui/images/face/11.gif HTTP/2.0" 404 15994 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
211.149.133.225 - - [04/Oct/2026:07:32:10 +0200] "GET /adminsoft/index.php?archive=adminuser&action=login HTTP/2.0" 404 15994 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
211.149.133.225 - - [04/Oct/2026:07:32:10 +0200] "GET /public/ui/met/images/dt-9.gif HTTP/2.0" 404 15994 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
211.149.133.225 - - [04/Oct/2026:07:32:10 +0200] "GET /order/alipay/images/alipay.gif HTTP/2.0" 404 15994 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
๐ฌ๐ง
consul.to
2026-10-02 21:03:30
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ฑ๐ป
garmtech.com
2026-10-02 19:48:10
(1 week ago)
Attempted access to sensitive endpoint (/includes/cls_sms.php) detected. Automated scan or unauthori ...
show more
Attempted access to sensitive endpoint (/includes/cls_sms.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-02 13:27:34
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:11:05
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 211.149.133.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 211.149.133.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:10:53.518054 2026] [security2:error] [pid 645:tid 645] [client 211.149.133.225:56552] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bonvivantorganics.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bonvivantorganics.com"] [uri "/okok.cer"] [unique_id "ar91Hc-4vCGoXHpnziEXNAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-10-01 11:43:50
(1 week ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-10-01 04:53:23
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:35:11
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 211.149.133.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 211.149.133.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:34:59.105380 2026] [security2:error] [pid 3731:tid 3731] [client 211.149.133.225:33704] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tgcindustrial.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tgcindustrial.com"] [uri "/okok.cer"] [unique_id "arzz4_b32hJQMK6VK6KxpQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-28 18:50:37
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 15:58:34
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 211.149.133.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 211.149.133.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 11:58:24.885730 2026] [security2:error] [pid 28277:tid 28277] [client 211.149.133.225:34288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iconbizpromo.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iconbizpromo.com"] [uri "/okok.cer"] [unique_id "ark9IC09xPE_1-jJzcqNGwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack