๐จ๐ณ
ThreatBook.io
2025-06-28 01:11:42
(1 year ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/4.196.100.145
2025-06- ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/4.196.100.145
2025-06-27 17:33:16 /web.config
2025-06-27 17:33:03 /config.php
2025-06-27 17:32:40 /
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 20:57:39
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 16:57:34.472604 2025] [security2:error] [pid 780217:tid 780217] [client 4.196.100.145:56356] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||victorvictor.biz|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "victorvictor.biz"] [uri "/dump.sql"] [unique_id "aF8FvtSX2dnhUVt4w-0MEQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 11:07:38
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 07:07:30.902481 2025] [security2:error] [pid 2597221:tid 2597221] [client 4.196.100.145:38216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wea-inc.com"] [uri "/.env"] [unique_id "aF57cnalBrtHkZV6yTk32gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 07:15:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 03:15:01.480162 2025] [security2:error] [pid 625685:tid 625723] [client 4.196.100.145:52536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "losersoftheyear.net"] [uri "/.env.production"] [unique_id "aF5E9eqoas6IhLQRmq1reQAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2025-06-27 05:19:16
(1 year ago)
Scanning for exploits - /.env.production
Web App Attack
๐ธ๐ช
Xpektor
2025-06-27 05:16:00
(1 year ago)
Scanning for vulnerabilities
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 01:18:58
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 26 21:18:52.578573 2025] [security2:error] [pid 1889857:tid 1889857] [client 4.196.100.145:60200] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||firejasstrio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "firejasstrio.com"] [uri "/db_dump.sql"] [unique_id "aF3xfIbAfb4ljXMTbWgOnwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-06-26 17:16:58
(1 year ago)
(bad_user_agent) srv104 Bad User-Agent 4.196.100.145 (AU/Australia/-): 10 in the last 3600 secs; Por ...
show more
(bad_user_agent) srv104 Bad User-Agent 4.196.100.145 (AU/Australia/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
LRob
2025-06-26 13:30:20
(1 year ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
LRob
2025-06-26 13:00:23
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ฉ๐ช
LRob
2025-06-26 12:45:13
(1 year ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐บ๐ธ
TPI-Abuse
2025-06-26 12:18:42
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 26 08:18:34.559202 2025] [security2:error] [pid 2113723:tid 2113723] [client 4.196.100.145:59220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kriske.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kriske.com"] [uri "/db_dump.sql"] [unique_id "aF06mlwjvl4TDyZ8nkfZLAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-06-26 07:53:14
(1 year ago)
(bad_user_agent) srv101 Bad User-Agent 4.196.100.145 (AU/Australia/-): 10 in the last 3600 secs; Por ...
show more
(bad_user_agent) srv101 Bad User-Agent 4.196.100.145 (AU/Australia/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-26 05:45:10
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 26 01:45:03.414282 2025] [security2:error] [pid 2128532:tid 2128532] [client 4.196.100.145:47326] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ldwla.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ldwla.com"] [uri "/db_dump.sql"] [unique_id "aFzeX0vmRcYH6uowLvJNZgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-25 23:37:48
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 4.196.100.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 19:37:41.128514 2025] [security2:error] [pid 824646:tid 824646] [client 4.196.100.145:59070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "patandmat.com"] [uri "/.env.local"] [unique_id "aFyIRdW3FXeFx8VIvoo5UAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack