๐บ๐ธ
TPI-Abuse
2026-06-12 20:20:40
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 16:20:33.046883 2026] [security2:error] [pid 13038:tid 13038] [client 36.161.111.94:52466] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||basse.me|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "basse.me"] [uri "/"] [unique_id "aixqEfpB9ZkB-msZ8cdKFAAAAAI"], referer: https://basse.me/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 20:09:15
(4 weeks ago)
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 16:09:07.953926 2026] [security2:error] [pid 6961:tid 6961] [client 36.161.111.94:53105] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.bioterrorismbooks.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.bioterrorismbooks.com"] [uri "/"] [unique_id "agYr48LS_XMDwdTGg8VjCwAAAAc"], referer: http://www.bioterrorismbooks.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-05-05 22:53:52
(1 month ago)
ThreatBook Intelligence: Mobile more details on http://threatbook.io/ip/36.161.111.94
2026-05-05 11: ...
show more
ThreatBook Intelligence: Mobile more details on http://threatbook.io/ip/36.161.111.94
2026-05-05 11:39:19 /config.json
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 12:12:49
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 08:12:42.413471 2026] [security2:error] [pid 3822430:tid 3822430] [client 36.161.111.94:52232] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.wedemandavote.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.wedemandavote.com"] [uri "/"] [unique_id "aeoMum0kFolTFva2fsMM8gAAAAQ"], referer: http://www.wedemandavote.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 13:47:16
(2 months ago)
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 09:47:07.735437 2026] [security2:error] [pid 16871:tid 16871] [client 36.161.111.94:52364] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||selfdirecteddiscovery.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "selfdirecteddiscovery.com"] [uri "/"] [unique_id "ac5zW1p1UZs_f-GSuqaVXQAAACE"], referer: http://selfdirecteddiscovery.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-03-31 22:30:13
(2 months ago)
ThreatBook Intelligence: Mobile more details on http://threatbook.io/ip/36.161.111.94
2026-03-31 02: ...
show more
ThreatBook Intelligence: Mobile more details on http://threatbook.io/ip/36.161.111.94
2026-03-31 02:33:02 /robots.txt
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 22:27:00
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 17:26:55.328288 2026] [security2:error] [pid 11877:tid 11877] [client 36.161.111.94:32154] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||engravingbyangela.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "engravingbyangela.com"] [uri "/"] [unique_id "aZJIL8f0DIkXTJ2AkHNstgAAAA4"], referer: https://engravingbyangela.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-29 22:40:49
(4 months ago)
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 17:40:42.904429 2026] [security2:error] [pid 8416:tid 8552] [client 36.161.111.94:32293] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.mikall.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.mikall.com"] [uri "/"] [unique_id "aXvh6oQxw7NQF6uzTB1-nAAAAJY"], referer: http://www.mikall.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-29 21:03:45
(4 months ago)
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.161.111.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 16:03:40.549240 2026] [security2:error] [pid 2913722:tid 2913722] [client 36.161.111.94:32132] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.tmcenvironment.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.tmcenvironment.com"] [uri "/"] [unique_id "aXvLLKPvBkPEIi6Fu9Ta8wAAAAA"], referer: http://www.tmcenvironment.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-11-25 22:37:19
(6 months ago)
ThreatBook Intelligence: Zombie,Mobile more details on https://threatbook.io/ip/36.161.111.94
2025-1 ...
show more
ThreatBook Intelligence: Zombie,Mobile more details on https://threatbook.io/ip/36.161.111.94
2025-11-25 04:37:18 /favicon.ico
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-07-18 22:36:20
(10 months ago)
ThreatBook Intelligence: Mobile more details on http://threatbook.io/ip/36.161.111.94
2025-07-18 05: ...
show more
ThreatBook Intelligence: Mobile more details on http://threatbook.io/ip/36.161.111.94
2025-07-18 05:58:46 /config.json
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-07-14 22:41:10
(10 months ago)
ThreatBook Intelligence: Mobile more details on http://threatbook.io/ip/36.161.111.94
2025-07-14 11: ...
show more
ThreatBook Intelligence: Mobile more details on http://threatbook.io/ip/36.161.111.94
2025-07-14 11:19:35 /explore/projects?non_archived=true&page=2&sort=latest_activity_desc
show less
Web App Attack