๐บ๐ธ
TPI-Abuse
2026-04-04 13:55:55
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 94.154.127.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 94.154.127.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:55:52.265409 2026] [security2:error] [pid 19592:tid 19592] [client 94.154.127.22:10421] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dmasoftlab.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dmasoftlab.com"] [uri "/"] [unique_id "adEYaBQw-6K56fooEaUs1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
wil.com
2024-09-24 05:30:18
(1 year ago)
GlobalProtect login attempts with user kbecker.
VPN IP
Brute-Force
๐ต๐ฑ
sefinek.net
2024-08-30 12:07:29
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/68.0.3440.75 Mobile/13G34 Safari/604.1 - -
show less
Bad Web Bot
๐ฌ๐ง
Swiptly
2024-08-25 00:57:52
(1 year ago)
Multiple critical ModSecurity events
...
Web Spam
Bad Web Bot
๐บ๐ธ
Jimbocous
2024-07-02 06:13:00
(1 year ago)
94.154.127.22 - - [01/Jul/2024:23:52:18 -0600] "GET /remote/login HTTP/1.1" "" "-" "Mozilla/5.0 (Win ...
show more
94.154.127.22 - - [01/Jul/2024:23:52:18 -0600] "GET /remote/login HTTP/1.1" "" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203"
94.154.127.22 - - [01/Jul/2024:23:52:21 -0600] "GET /login HTTP/1.1" "" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203"
fail2ban [apache-auth] Banned 94.154.127.22 - 2024-07-01 23:52:21
Unauthorized connection attempts via HTTP direct to IP Address bypassing DNS.
Targeting known vulnerabilities.
show less
Hacking
Web App Attack
๐บ๐ธ
Jimbocous
2024-07-02 05:52:00
(1 year ago)
94.154.127.22 - - [01/Jul/2024:23:52:18 -0600] "GET /remote/login HTTP/1.1" "" "-" "Mozilla/5.0 (Win ...
show more
94.154.127.22 - - [01/Jul/2024:23:52:18 -0600] "GET /remote/login HTTP/1.1" "" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203"
94.154.127.22 - - [01/Jul/2024:23:52:21 -0600] "GET /login HTTP/1.1" "" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203"
fail2ban [apache-auth] Banned 94.154.127.22 - 2024-07-01 23:52:21
Unauthorized connection attempts via HTTP/Other direct to IP Address bypassing DNS.
Targeting known vulnerabilities.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-26 03:53:44
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 94.154.127.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 94.154.127.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 25 22:53:37.461559 2024] [security2:error] [pid 14756] [client 94.154.127.22:44267] [client 94.154.127.22] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Dalton II/Thumbs.db"] [unique_id "ZdwLQehrmfX07qqvdVnXtwAAAA8"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Dalton%20II/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-10-30 23:39:00
(2 years ago)
"Illegal redirection attempt"
Brute-Force
๐จ๐ญ
backslash
2023-10-27 15:30:19
(2 years ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ฉ๐ช
niceshops.com
2023-09-24 00:01:18
(2 years ago)
Web Attack ([23/Sep/2023:23:47:41.335] GET /%7Burl%7D/hoptimist?beid=8590ac062555493444893ec5871609d ...
show more
Web Attack ([23/Sep/2023:23:47:41.335] GET /%7Burl%7D/hoptimist?beid=8590ac062555493444893ec5871609dffedf8cf684d93f7533bc52ffc5611dc8&bid=08490295488a1189099751ebeddb5992313dd2a831e07a92e66d196ddc261777)
show less
Web App Attack
๐จ๐ญ
backslash
2023-09-15 06:23:47
(2 years ago)
honeypot
Bad Web Bot
๐ซ๐ฎ
bittiguru.fi
2023-08-27 22:56:55
(2 years ago)
94.154.127.22 - [28/Aug/2023:01:56:47 +0300] "POST /fi/matkailu/sinun-lomasi/nahtavyydet-ja-kayntiko ...
show more
94.154.127.22 - [28/Aug/2023:01:56:47 +0300] "POST /fi/matkailu/sinun-lomasi/nahtavyydet-ja-kayntikohteet-teemoittain/museot-ja-historialliset-kohteet/pielisen-museo/xmlrpc.php HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36" "-"
94.154.127.22 - [28/Aug/2023:01:56:54 +0300] "POST /fi/matkailu/sinun-lomasi/nahtavyydet-ja-kayntikohteet-teemoittain/museot-ja-historialliset-kohteet/pielisen-museo/xmlrpc.php HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36" "-"
...
show less
Hacking
Brute-Force
Web App Attack