๐ฌ๐ง
consul.to
2026-10-09 09:55:59
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 15:46:53
(1 day ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-07 22:40:01
(1 day ago)
crowdsecurity/http-backdoors-attempts
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-10-07 17:33:44
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
IRISIO
2026-10-07 16:42:52
(2 days ago)
scans/SQL injection/spam posts : 93 queries
Web App Attack
SQL Injection
๐ธ๐ช
vaia.cloud
2026-10-07 01:45:01
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:29:18
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:29:12.536451 2026] [security2:error] [pid 23345:tid 23345] [client 8.153.160.5:35694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.zmgmt.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.zmgmt.com"] [uri "/okok.cer"] [unique_id "asWESCEf3AqcLZda-Mx3FAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:54:13
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:54:07.104548 2026] [security2:error] [pid 18677:tid 18677] [client 8.153.160.5:54008] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lexvaz.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lexvaz.com"] [uri "/okok.cer"] [unique_id "asUnrzJS-zqP2UCdGT9NCwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-03 18:00:32
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 11:27:42
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 07:27:35.253582 2026] [security2:error] [pid 17255:tid 17255] [client 8.153.160.5:55712] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.prcomputersolutions.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.prcomputersolutions.com"] [uri "/okok.cer"] [unique_id "asDmp0rQfd65N9yJnCFnXwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 06:16:09
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:16:01.991723 2026] [security2:error] [pid 31730:tid 31730] [client 8.153.160.5:36442] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lamanchaorchards.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lamanchaorchards.com"] [uri "/okok.cer"] [unique_id "asCdoSqkcdNR7xZHWpZotQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:00:46
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:00:40.967818 2026] [security2:error] [pid 5052:tid 5052] [client 8.153.160.5:42878] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.debbieweibler.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.debbieweibler.com"] [uri "/okok.cer"] [unique_id "ar_jOEYltrrru_DpnOza0AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-02 00:07:12
(1 week ago)
8.153.160.5 - - [02/Oct/2026:02:07:09 +0200] "GET /public/images/metinfo.gif HTTP/1.1" 404 458 "-" " ...
show more
8.153.160.5 - - [02/Oct/2026:02:07:09 +0200] "GET /public/images/metinfo.gif HTTP/1.1" 404 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
8.153.160.5 - - [02/Oct/2026:02:07:09 +0200] "GET /Home/Tpl/default/Index/c_index.html HTTP/1.1" 404 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
8.153.160.5 - - [02/Oct/2026:02:07:09 +0200] "GET /ucms/img/loading.gif HTTP/1.1" 404 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
8.153.160.5 - - [02/Oct/2026:02:07:09 +0200] "GET /app/img/loading.gif HTTP/1.1" 404 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
8.153.160.5 - - [02/Oct/2026:02:07:09 +0200] "GET /zb_users/emotion/face/Music.gif HTTP/1.1" 404 4424 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
show less
Bad Web Bot
๐ฉ๐ช
pscriptos
2026-10-01 21:41:45
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 03:32:22
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 8.153.160.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:32:17.291750 2026] [security2:error] [pid 29548:tid 29548] [client 8.153.160.5:50648] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vittariabeauty.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vittariabeauty.com"] [uri "/okok.cer"] [unique_id "ar3UQYDt6jVIngGh0BtiIgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack