๐ฎ๐ฉ
Burayot
2025-10-28 14:26:22
(11 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 94.131.49.209 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 94.131.49.209 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2025-10-28 12:04:54
(11 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-17 00:21:32
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 20:21:25.846074 2025] [security2:error] [pid 27362:tid 27362] [client 94.131.49.209:53011] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cruisedawgs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cruisedawgs.com"] [uri "/site-backup.sql"] [unique_id "aPGMBS9hPECrk4WE3dBGnwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-16 23:21:03
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 19:21:00.520001 2025] [security2:error] [pid 25756:tid 25756] [client 94.131.49.209:33651] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sfholidayrentals.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sfholidayrentals.com"] [uri "/dump.sql"] [unique_id "aPF93Nnqxo311A34EInxaQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-16 00:23:45
(11 months ago)
SSL VPN bruteforce detected
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-14 22:21:17
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 14 18:21:10.003888 2025] [security2:error] [pid 26104:tid 26104] [client 94.131.49.209:50289] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||havelocktruckandauto.ca|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "havelocktruckandauto.ca"] [uri "/backup.sql"] [unique_id "aO7M1Rh8h2_mX6AAO2rorgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-12 10:45:01
(11 months ago)
94.131.49.209 - - [12/Oct/2025:10:45:00 +0000] "GET /wordpress.tar.gz HTTP/1.1" 404 47027 "-" "Mozil ...
show more
94.131.49.209 - - [12/Oct/2025:10:45:00 +0000] "GET /wordpress.tar.gz HTTP/1.1" 404 47027 "-" "Mozilla/5.0 (Linux; Android 12; SM-G991B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Mobile Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2025-10-12 10:12:11
(11 months ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-11 11:31:27
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 07:31:22.776738 2025] [security2:error] [pid 8436:tid 8443] [client 94.131.49.209:26861] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||culturallyyours.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "culturallyyours.org"] [uri "/wp-content/uploads/localhost.sql"] [unique_id "aOpACguSI_6sgg5w6OVq0gAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 21:12:50
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 17:12:42.366976 2025] [security2:error] [pid 13421:tid 13421] [client 94.131.49.209:56641] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gonzalez.com"] [uri "/wp-content/backup/wp-config.php~"] [unique_id "aOglSi_DH5ei7JLRk5S5QAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 18:21:04
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 14:20:57.029020 2025] [security2:error] [pid 9478:tid 9478] [client 94.131.49.209:31189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trlservice.com"] [uri "/wp-content/uploads/wp-config.php.old"] [unique_id "aOf9CY8P1lFHXXEaarQboAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 17:58:36
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 13:58:31.838336 2025] [security2:error] [pid 8425:tid 8425] [client 94.131.49.209:26363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsdepot.com"] [uri "/wp-content/uploads/wp-config.php.old"] [unique_id "aOf3xyxm-o-fFCkfdLzIJAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-09 16:00:23
(11 months ago)
| Suspicious URL access.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 08:59:09
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 04:59:05.416380 2025] [security2:error] [pid 8293:tid 8293] [client 94.131.49.209:25793] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "renjunews.com"] [uri "/wp-content/wp-config.php.bak"] [unique_id "aOd5WW6Tlk0n-2_KaOv2wQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 06:38:38
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.131.49.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 02:38:34.576969 2025] [security2:error] [pid 16622:tid 16622] [client 94.131.49.209:17237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zacharycollard.com"] [uri "/backup/wp-config.php.old"] [unique_id "aOdYauKAf9yk0bnFPhEEIAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack