๐ฏ๐ต
S.O.B.A. Dev.
2026-03-15 13:00:27
(4 months ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐ณ๐ฟ
Tripwire
2026-03-14 17:37:41
(4 months ago)
Scanning for exploits - /backup/backup.tar.gz
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-03-12 19:44:35
(4 months ago)
98.159.226.177 - - [12/Mar/2026:19:44:23 +0000] "GET /bak/index.zip HTTP/1.1" 404 196 "-" "-"
Web App Attack
๐ฉ๐ช
bescared
2026-03-11 20:57:19
(4 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-03-09 14:50:56
(4 months ago)
Web app vulnerability scanning detected. Evidence: 98.159.226.177 - - [09/Mar/2026:14:50:54 +0000] " ...
show more
Web app vulnerability scanning detected. Evidence: 98.159.226.177 - - [09/Mar/2026:14:50:54 +0000] "GET /backup/index.zip HTTP/1.1" 404 45102 "-" "-"
98.159.226.177 - - [09/Mar/2026:14:50:56 +0000] "HEAD /backup.sql HTTP/1.1" 404 4147 "-" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 02:20:28
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 21:20:20.303051 2026] [security2:error] [pid 7128:tid 7128] [client 98.159.226.177:45769] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||medicalexchangeasinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "medicalexchangeasinc.com"] [uri "/sql.sql"] [unique_id "aajoZHnuz8TZEaCfooltCgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-03-02 20:04:44
(4 months ago)
/archive.zip
Hacking
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-03-01 20:50:57
(4 months ago)
Suspicious HTTP(s) activity without a user agent provided
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-01 01:40:58
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 20:40:49.889468 2026] [security2:error] [pid 23941:tid 23941] [client 98.159.226.177:64915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spectorworld.com"] [uri "/backup/sftp-config.json"] [unique_id "aaOZIZs-7YgESHII7ppFfAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 22:53:09
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 17:53:02.656966 2026] [security2:error] [pid 28100:tid 28100] [client 98.159.226.177:41059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "russiacoin.info"] [uri "/back/sftp-config.json"] [unique_id "aaDOzgw7Y2LgWgR79w2aWwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 04:16:36
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 23:16:29.056786 2026] [security2:error] [pid 30813:tid 30813] [client 98.159.226.177:23663] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||linnardfinancial.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "linnardfinancial.com"] [uri "/mysql.sql"] [unique_id "aZ_JHUrveNQkSeyKTRXvpwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-02-24 06:29:37
(5 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-16 05:17:28
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 00:17:21.437220 2026] [security2:error] [pid 9358:tid 9358] [client 98.159.226.177:40671] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kwtlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kwtlaw.com"] [uri "/restore/sql.sql"] [unique_id "aZKoYek3sMm1YHiw6sWW-gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-02-16 05:08:57
(5 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 00:28:49
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 19:28:39.987191 2026] [security2:error] [pid 9428:tid 9428] [client 98.159.226.177:31481] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barnesandbrower.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barnesandbrower.com"] [uri "/backup/backup.sql"] [unique_id "aY5wN0KxcybzUQWovRvjAAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack