๐บ๐ธ
TPI-Abuse
2026-05-24 12:50:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 08:50:28.172276 2026] [security2:error] [pid 17747:tid 17747] [client 44.203.69.195:56641] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||acpb.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "acpb.net"] [uri "/dbdump.sql"] [unique_id "ahL0FNmyfG8tZ1wXf5kqhAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-05-24 12:40:53
(1 week ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-05-24 11:59:51
(1 week ago)
Web scanning / probing for vulnerable paths | URL: /site.sql | Evidence: microsites.grupoeuropa.com ...
show more
Web scanning / probing for vulnerable paths | URL: /site.sql | Evidence: microsites.grupoeuropa.com 44.203.69.195 - - [24/May/2026:13:59:01 +0200] \"GET /site.sql HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0\" GEOIP_COUNTRY_CODE=US | ASN: AMAZON-AES | Country: US
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-24 11:47:51
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 07:47:45.783816 2026] [security2:error] [pid 24139:tid 24139] [client 44.203.69.195:61353] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||armandselmwoodpark.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "armandselmwoodpark.com"] [uri "/data.sql"] [unique_id "ahLlYQ3jNOBAIY_9o-WIbgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-24 10:34:47
(1 week ago)
44.203.69.195 - - [24/May/2026:13:34:43 +0300] "GET /wp-content/uploads/dump.sql HTTP/1.1" 404 3169 ...
show more
44.203.69.195 - - [24/May/2026:13:34:43 +0300] "GET /wp-content/uploads/dump.sql HTTP/1.1" 404 3169 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
44.203.69.195 - - [24/May/2026:13:34:47 +0300] "GET /wp-content/uploads/backup.sql HTTP/1.1" 404 3168 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-24 03:13:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 23:13:07.368594 2026] [security2:error] [pid 9442:tid 9442] [client 44.203.69.195:57913] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||backstore.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backstore.com"] [uri "/database.sql"] [unique_id "ahJsw6GIVylG3U65tlvhiAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-24 02:07:30
(1 week ago)
Web attack
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 23:36:27
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 19:36:22.476293 2026] [security2:error] [pid 27808:tid 27808] [client 44.203.69.195:60526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.spyasociados.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.spyasociados.com"] [uri "/database.sql"] [unique_id "ahI59n-D-8XoyP6janRlsAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-23 22:05:12
(1 week ago)
Scanning/Probing (70)
Brute-Force
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-05-23 21:14:25
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 44.203.69.195 (US/United States/ec2-44- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 44.203.69.195 (US/United States/ec2-44-203-69-195.compute-1.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-05-23 13:11:06
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 44.203.69.195 (ec2-44-203-69-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 09:11:02.636305 2026] [security2:error] [pid 5536:tid 5536] [client 44.203.69.195:59729] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.savoiapower.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.savoiapower.com"] [uri "/data.sql"] [unique_id "ahGnZptyVp2Nl9SF4Nj_TwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-05-23 12:35:02
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-23 12:28:43
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-05-23 07:15:01
(1 week ago)
ModSecurity rule 949110 triggered on wp1. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ฉ๐ช
EGP Abuse Dept
2026-05-23 06:12:54
(1 week ago)
Scanning for web/db/file exploits on www.restaurantlemoulin.nl
SQL Injection
Bad Web Bot
Web App Attack