๐ซ๐ท
mikekarl
2026-03-15 02:21:21
(5 months ago)
Empty or bad user-agent.
Bad Web Bot
๐ต๐พ
armandosaucedo.me
2026-03-12 19:44:27
(5 months ago)
98.159.226.181 - - [12/Mar/2026:19:44:22 +0000] "HEAD /bak/dump.sql HTTP/1.1" 403 - "-" "-"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 01:19:52
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 21:19:43.703375 2026] [security2:error] [pid 11079:tid 11079] [client 98.159.226.181:64493] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wendeenicole.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wendeenicole.com"] [uri "/bak/mysql.sql"] [unique_id "abIUrx1OF-jkE8uA56__HgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 00:33:20
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 20:33:12.948633 2026] [security2:error] [pid 2721:tid 2721] [client 98.159.226.181:25709] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||matteozacchino.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "matteozacchino.dev"] [uri "/sql.sql"] [unique_id "abC4SLddjBpRHoYO5pLl-wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-10 21:40:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 17:40:14.482780 2026] [security2:error] [pid 23710:tid 23710] [client 98.159.226.181:60293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3dcounty.com"] [uri "/backup/sftp-config.json"] [unique_id "abCPvn4DnXJGYs8nIgNPtAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-03-03 04:41:38
(5 months ago)
[03/Mar/2026:05:41:35 +0100] 177251289581.757862 98.159.226.181 44671 217.154.7.177 80
[03/Mar/2026: ...
show more
[03/Mar/2026:05:41:35 +0100] 177251289581.757862 98.159.226.181 44671 217.154.7.177 80
[03/Mar/2026:05:41:35 +0100] 17725128952.953982 98.159.226.181 63757 217.154.7.177 443
[03/Mar/2026:05:41:37 +0100] 177251289791.173644 98.159.226.181 50631 217.154.7.177 80
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-03-02 20:17:22
(5 months ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐ฏ๐ต
Valhalla
2026-03-02 20:04:42
(5 months ago)
/backup/bak.gz
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 01:24:11
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 20:24:04.848700 2026] [security2:error] [pid 1689:tid 1689] [client 98.159.226.181:33169] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.spectorworld.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.spectorworld.com"] [uri "/restore/www.sql"] [unique_id "aaTmtC63hjAzrzrcNNQOhwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 01:00:36
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 20:00:29.067491 2026] [security2:error] [pid 11571:tid 11571] [client 98.159.226.181:50437] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kwtlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kwtlaw.com"] [uri "/back/backup.sql"] [unique_id "aaThLTQFRrjaxywaBU-ERAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-03-01 06:05:08
(5 months ago)
attempted to access /backups/website.gz
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 03:00:22
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 22:00:17.474682 2026] [security2:error] [pid 20454:tid 20454] [client 98.159.226.181:21273] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dudleyanddudley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dudleyanddudley.com"] [uri "/backup.sql"] [unique_id "aaOrwXRkibfww819NniZpQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 01:42:09
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 20:42:01.514555 2026] [security2:error] [pid 17982:tid 17982] [client 98.159.226.181:58367] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lusocleaningservice.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lusocleaningservice.com"] [uri "/backup/sql.sql"] [unique_id "aaOZaWJRtyw5g0uIE4vxzAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-02-27 19:08:02
(5 months ago)
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by pol ...
show more
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by policy||proxy-server.link|F|2 Phase: 2 Severity: CRITICAL URI: /back/dump.sql Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-02-25 21:06:23
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 16:06:16.085710 2026] [security2:error] [pid 18537:tid 18537] [client 98.159.226.181:35035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jussetcotradinglimited.co"] [uri "/sftp-config.json"] [unique_id "aZ9kSJdEHw5Us0FWPpnXTQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack