๐ฉ๐ช
filstal.org
2026-03-15 06:15:26
(5 months ago)
Vulnerability scan activity detected by Fail2Ban
Hacking
Web App Attack
๐ฉ๐ช
David Ferneding
2026-03-14 22:59:49
(5 months ago)
Blocked by UFW (TCP on 80)
Source port: 26091
TTL: 56
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 26091
TTL: 56
Packet length: 60
TOS: 0x00
This report (for 98.159.226.180) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 04:26:16
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 00:26:11.581715 2026] [security2:error] [pid 12026:tid 12026] [client 98.159.226.180:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eddysgroup.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eddysgroup.com"] [uri "/old/backup.sql"] [unique_id "abOR4673avLye6cQnsXjbAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-03-12 19:44:39
(5 months ago)
98.159.226.180 - - [12/Mar/2026:19:44:24 +0000] "HEAD /restore/backup.sql HTTP/1.1" 403 - "-" "-"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 01:19:51
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 21:19:47.066955 2026] [security2:error] [pid 9779:tid 9779] [client 98.159.226.180:32559] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wendeenicole.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wendeenicole.com"] [uri "/sql.sql"] [unique_id "abIUs7Wcrq37mCLLufXc3QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mikekarl
2026-03-11 11:49:01
(5 months ago)
Empty or bad user-agent.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-11 00:33:09
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 20:33:01.420562 2026] [security2:error] [pid 3024:tid 3024] [client 98.159.226.180:40083] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||matteozacchino.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "matteozacchino.dev"] [uri "/old/www.sql"] [unique_id "abC4PYG8TzH6PQDe1lkBnAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 14:19:46
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 10:19:41.060257 2026] [security2:error] [pid 29994:tid 29994] [client 98.159.226.180:28293] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lusocleaningservice.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lusocleaningservice.com"] [uri "/back/dump.sql"] [unique_id "aa7W_XvC9PctipvDoc9ogAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-03-03 04:41:35
(5 months ago)
[03/Mar/2026:05:41:34 +0100] 177251289478.225610 98.159.226.180 23817 217.154.7.177 443
[03/Mar/2026 ...
show more
[03/Mar/2026:05:41:34 +0100] 177251289478.225610 98.159.226.180 23817 217.154.7.177 443
[03/Mar/2026:05:41:34 +0100] 177251289480.006504 98.159.226.180 46073 217.154.7.177 80
[03/Mar/2026:05:41:34 +0100] 177251289441.794580 98.159.226.180 32763 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-03-02 20:17:26
(5 months ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐ฏ๐ต
Valhalla
2026-03-02 20:04:54
(5 months ago)
/old/bak.rar
Hacking
Web App Attack
๐ฌ๐ง
Axel
2026-03-02 19:16:02
(5 months ago)
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by pol ...
show more
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by policy||ipvi.network|F|2 Phase: 2 Severity: CRITICAL URI: /backups/backup.sql Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
itsolon
2026-03-01 11:37:35
(5 months ago)
[01/Mar/2026:12:37:29 +0100] 177236504916.617010 98.159.226.180 43901 217.154.7.177 80
[01/Mar/2026: ...
show more
[01/Mar/2026:12:37:29 +0100] 177236504916.617010 98.159.226.180 43901 217.154.7.177 80
[01/Mar/2026:12:37:32 +0100] 177236505220.425361 98.159.226.180 23475 217.154.7.177 443
[01/Mar/2026:12:37:34 +0100] 177236505440.628601 98.159.226.180 42407 217.154.7.177 80
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 20:50:40
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 15:50:36.689626 2026] [security2:error] [pid 12863:tid 12863] [client 98.159.226.180:20527] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.domainexecs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.domainexecs.com"] [uri "/back/dump.sql"] [unique_id "aaNVHObe-lFkMYlNUERIfAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-02-27 19:08:03
(5 months ago)
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by pol ...
show more
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by policy||proxy-server.link|F|2 Phase: 2 Severity: CRITICAL URI: /restore/mysql.sql Server: UK-01
show less
Web App Attack
Hacking
SQL Injection