๐บ๐ธ
TPI-Abuse
2026-09-29 13:43:07
(2 days ago)
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:43:01.065510 2026] [security2:error] [pid 1681:tid 1681] [client 223.88.80.139:37224] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.whiterhinogroup.net|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.whiterhinogroup.net"] [uri "/"] [unique_id "arvAZcklwMXVaPwCGqdOfgAAAAc"], referer: http://www.whiterhinogroup.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-09-28 23:44:32
(3 days ago)
29/Sep/2026:01:44:32.012486 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Sep/2026:01:44:32.012486 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 223.88.80.139] ModSecurity: Warning. Match of "rx ^urlgrabber/[0-9\\\\\\\\.]+ yum/[0-9\\\\\\\\.]+$" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "53"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: user-agent: found within REQUEST_HEADERS:User-Agent: user-agent:mozilla/5.0 (windows nt 6.1; wow64) applewebkit/537.36 (khtml, like gecko) chrome/50.0.2661.102 safari/537.36"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "hwagm.elhacker.net"] [uri "/truth-bitcoin/"] [unique_id "arr74O6b4ONvkUd-10VOzAABijI"]
...
show less
Hacking
Web App Attack
๐ฎ๐น
mgarofano80
2026-09-11 23:48:28
(2 weeks ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 21:03:16
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 17:03:09.490173 2026] [security2:error] [pid 13727:tid 13727] [client 223.88.80.139:38663] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||astglobaltech.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "astglobaltech.com"] [uri "/"] [unique_id "aj7pDcJq4wJt4JRKij7M8QAAAAU"], referer: http://astglobaltech.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 22:20:43
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 18:20:38.327939 2026] [security2:error] [pid 32370:tid 32370] [client 223.88.80.139:13318] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||arroceraomoa.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "arroceraomoa.com"] [uri "/"] [unique_id "aiCotkpJh0d1XCemplRb8QAAAAY"], referer: http://arroceraomoa.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 18:29:50
(4 months ago)
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 14:29:42.372574 2026] [security2:error] [pid 15780:tid 15780] [client 223.88.80.139:28845] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||bentonflybox.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "bentonflybox.com"] [uri "/index.htm"] [unique_id "agIgFuGO64CxLItbtqGKOwAAAAU"], referer: https://bentonflybox.com/index.htm
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-27 00:56:20
(7 months ago)
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 19:56:12.117452 2026] [security2:error] [pid 7558:tid 7741] [client 223.88.80.139:11668] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.exede-sales.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.exede-sales.com"] [uri "/index.html"] [unique_id "aaDrrMLffs5P_XPShJaPqwAAAIg"], referer: http://www.exede-sales.com/index.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
killian mei
2026-02-26 22:05:23
(7 months ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/223.88.80.139
2026-02- ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/223.88.80.139
2026-02-26 03:23:31 /favicon.ico
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-25 08:49:11
(7 months ago)
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 03:49:04.308984 2026] [security2:error] [pid 29222:tid 29222] [client 223.88.80.139:11482] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.title26.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.title26.com"] [uri "/"] [unique_id "aZ63gCLC6YVAFKD9N5rBdgAAAAE"], referer: https://www.title26.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-31 05:16:24
(8 months ago)
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 223.88.80.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 31 00:16:18.002810 2026] [security2:error] [pid 3384:tid 3384] [client 223.88.80.139:19980] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.forwardti.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.forwardti.com"] [uri "/"] [unique_id "aX2QIvDZJk6_gGyfjaUIiQAAAAY"], referer: https://www.forwardti.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-05-24 22:11:11
(1 year ago)
ThreatBook Intelligence: Zombie,Gateway more details on https://threatbook.io/ip/223.88.80.139
2025- ...
show more
ThreatBook Intelligence: Zombie,Gateway more details on https://threatbook.io/ip/223.88.80.139
2025-05-24 04:02:52 /sitemap.xml
show less
Web App Attack