๐บ๐ธ
TPI-Abuse
2026-07-18 09:08:18
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 05:08:14.557332 2026] [security2:error] [pid 1809159:tid 1809159] [client 41.62.234.174:10948] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gubbio.name|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gubbio.name"] [uri "/wp-content/wphb-logs/api-debug.log"] [unique_id "altCfjMrx5fqr4v_sB5UQgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-18 08:40:51
(5 days ago)
41.62.234.174 - - [18/Jul/2026:11:40:51 +0300] "GET /wp-content/uploads/backup.sql HTTP/1.1" 404 650 ...
show more
41.62.234.174 - - [18/Jul/2026:11:40:51 +0300] "GET /wp-content/uploads/backup.sql HTTP/1.1" 404 650 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15"
41.62.234.174 - - [18/Jul/2026:11:40:51 +0300] "GET /wp-content/database.sql HTTP/1.1" 404 650 "-" "Mozilla/5.0 (SS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 07:19:12
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 03:19:06.081350 2026] [security2:error] [pid 192135:tid 192135] [client 41.62.234.174:16748] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "experimentalscene.com"] [uri "/conf.json"] [unique_id "also6kg7UziIpK4PL7SXDgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-18 07:07:43
(5 days ago)
Malicious web traffic detected by CrowdSec
Hacking
๐ณ๐ฑ
melroy89
2026-07-18 07:03:04
(5 days ago)
41.62.234.174 - - [18/Jul/2026:09:02:41 +0200] "GET /v2/api-docs HTTP/1.1" 404 207 "-" "Mozilla/5.0 ...
show more
41.62.234.174 - - [18/Jul/2026:09:02:41 +0200] "GET /v2/api-docs HTTP/1.1" 404 207 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" "blog.melroy.org" 0.000
41.62.234.174 - - [18/Jul/2026:09:02:41 +0200] "GET /v1/api-docs HTTP/1.1" 404 207 "-" "Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" "blog.melroy.org" 0.000
41.62.234.174 - - [18/Jul/2026:09:02:41 +0200] "GET /swagger/v1/swagger.yaml HTTP/1.1" 404 189 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0" "blog.melroy.org" 0.000
41.62.234.174 - - [18/Jul/2026:09:02:41 +0200] "GET /api-docs HTTP/1.1" 404 189 "-" "Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.20" "blog.melroy.org" 0.000
41.62.234.174 - - [18/Jul/2026:09:02:41 +0200] "GET /api-docs/swagger.json HTTP/1.1" 404 207 "-" "Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Geck
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 06:31:35
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 02:31:28.841437 2026] [security2:error] [pid 31532:tid 31532] [client 41.62.234.174:32931] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||danzadance.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danzadance.org"] [uri "/backup.sql"] [unique_id "alsdwAIvifSeM2p7mYyvmAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 06:03:34
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 02:03:28.623031 2026] [security2:error] [pid 1809524:tid 1809594] [client 41.62.234.174:53661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "docdalton.com"] [uri "/.env/%5C"] [unique_id "alsXMM091Rmi3JYktm-VSQAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 05:24:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 41.62.234.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 01:24:21.029190 2026] [security2:error] [pid 1743354:tid 1743354] [client 41.62.234.174:10397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clubfansite.com"] [uri "/.env"] [unique_id "alsOBTFcQvYOpIyCG_gULwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-08-02 23:13:07
(11 months ago)
HTTP1.x attacks
DDoS Attack