🇺🇸
TPI-Abuse
2026-08-03 23:10:15
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 4.235.121.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.235.121.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 19:10:06.442425 2026] [security2:error] [pid 7057:tid 7069] [client 4.235.121.121:58610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.docdalton.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.docdalton.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "anEfzgsZ2bggJCYpPCjRtwAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
ketovoila.pl
2026-08-03 23:05:20
(1 month ago)
ketovoila.pl web app/PHP backdoor scan: hits=1; unique_paths=1; sample_paths=/vendor/phpunit/phpunit ...
show more
ketovoila.pl web app/PHP backdoor scan: hits=1; unique_paths=1; sample_paths=/vendor/phpunit/phpunit/phpunit.xsd; UA="Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"; window=2026-08-03T23:05:20Z..2026-08-03T23:05:20Z
show less
Bad Web Bot
Web App Attack
🇦🇺
Anytech
2026-08-03 22:54:51
(1 month ago)
Blocked by Conn-Monitor: cve-exploit-paths
Hacking
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-03 17:08:38
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 4.235.121.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.235.121.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 13:08:31.374060 2026] [security2:error] [pid 3013495:tid 3013495] [client 4.235.121.121:63118] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||abraxasstudio.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "abraxasstudio.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "anDLD1WLiMUzN2UBLngmzgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gigatech
2026-08-03 14:10:04
(1 month ago)
Webserver Probing
Web App Attack
🇩🇪
FeG Deutschland
2026-08-03 13:12:14
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 12:00:38
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 4.235.121.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.235.121.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 08:00:31.334893 2026] [security2:error] [pid 2571897:tid 2571897] [client 4.235.121.121:57776] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||stbms.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stbms.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "anCC34ABhAIddTC_B-M2TgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 07:39:26
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 4.235.121.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.235.121.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 03:39:22.818572 2026] [security2:error] [pid 2380479:tid 2380479] [client 4.235.121.121:65296] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rimworld.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rimworld.com"] [uri "/notra/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "anBFqoNgBK3jmoHcB0pR2wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-03 05:53:14
(1 month ago)
4.235.121.121 - - [03/Aug/2026:05:25:18 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 40 ...
show more
4.235.121.121 - - [03/Aug/2026:05:25:18 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 13272 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
4.235.121.121 - - [03/Aug/2026:05:25:42 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 13272 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
4.235.121.121 - - [03/Aug/2026:05:26:02 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 13272 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
4.235.121.121 - - [03/Aug/2026:05:26:23 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 13272 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
4.235.121.121 - - [03/Aug/2026:05:53:11 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 13272 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
...
show less
Brute-Force
Web App Attack
🇩🇪
DocNetzwerk
2026-08-03 05:51:27
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 4.235.121.121 (NO/Norway/-)
SQL Injection
🇫🇷
digital-plus-experience.com
2026-08-03 04:54:31
(1 month ago)
Probe for vulnerabilities. Path attempted: /vendor/phpunit/phpunit/phpunit.xsd
Web App Attack