๐ต๐พ
armandosaucedo.me
2026-04-27 01:41:53
(4 months ago)
Threat Intelligence via ARMTI, Web Attack: GET //blog/
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 16:23:07
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 12:23:01.987730 2026] [security2:error] [pid 1589:tid 1589] [client 98.159.226.22:41999] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mindtoken.app|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mindtoken.app"] [uri "/back/backup.sql"] [unique_id "abGW5bkN6lkx1bEzbJFxTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-07 01:50:14
(5 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
๐ฌ๐ง
pinguin
2026-03-03 01:14:23
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /backups/dump.sql
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-03-02 20:30:10
(6 months ago)
Suspicious HTTP(s) activity without a user agent provided
Bad Web Bot
๐ณ๐ฟ
Tripwire
2026-03-01 20:36:55
(6 months ago)
Scanning for exploits - /backup/website.gz
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-27 17:20:39
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 12:20:34.382745 2026] [security2:error] [pid 9004:tid 9004] [client 98.159.226.22:34411] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||asiabeef.network|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "asiabeef.network"] [uri "/backup/sql.sql"] [unique_id "aaHSYpry_XSZJEAJ0OyO2wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-25 18:26:53
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 13:26:44.939925 2026] [security2:error] [pid 31421:tid 31421] [client 98.159.226.22:62497] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swhowell.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swhowell.com"] [uri "/backup/mysql.sql"] [unique_id "aZ8-5FK-_rQVNaGsStFzugAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-02-25 17:48:29
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
r3versedk
2026-02-23 13:57:37
(6 months ago)
๐ก๏ธ Automated Threat Report from maxjensen.dk
๐ฏ Attack Type: Botnet Fingerprint
๐จ Severity: CRITICAL ...
show more
๐ก๏ธ Automated Threat Report from maxjensen.dk
๐ฏ Attack Type: Botnet Fingerprint
๐จ Severity: CRITICAL
๐ Threat Score: 95/100
๐ Total Attacks: 330 (database verified, seen over today)
๐ Peak Score: 95/100
๐ฏ Common Types: Botnet Fingerprint(1x)
๐ Fingerprint: 9f96b00ce11bc787
๐ค AI/ML: ๐ค Multi-Model Consensus (neural-network, q-learning, gpt) - ๐ง NN (55%): throttle (94.9%) | ๐ฎ QL (23%): block (75.0%) | ๐ค GPT (23%): monitor (70.0%) | โ๏ธ dynamic+boosted weights...
Detected: 2026-02-23T13:57:37.383Z
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-15 02:31:23
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:31:18.530426 2026] [security2:error] [pid 9073:tid 9073] [client 98.159.226.22:32651] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||russiacoin.info|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "russiacoin.info"] [uri "/restore/mysql.sql"] [unique_id "aZEv9sSt70rXna58NXmFjgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-14 11:05:08
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 06:05:02.930971 2026] [security2:error] [pid 26471:tid 26471] [client 98.159.226.22:23183] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||powderriverinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "powderriverinc.com"] [uri "/bak/www.sql"] [unique_id "aZBW3k_b4VYilr5hIzROQgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 08:39:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 03:39:26.703281 2026] [security2:error] [pid 8473:tid 8488] [client 98.159.226.22:45715] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fishrapper.com"] [uri "/sftp-config.json"] [unique_id "aYruvkGxpccwe7JyOAWrSwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-08 04:34:47
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 23:34:44.054125 2026] [security2:error] [pid 30154:tid 30154] [client 98.159.226.22:30189] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pcga.golf|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pcga.golf"] [uri "/restore/backup.sql"] [unique_id "aYgSZBVjM0HVw13kOkn06wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-05 03:29:31
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 04 22:29:23.005746 2026] [security2:error] [pid 15615:tid 15615] [client 98.159.226.22:36731] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pellman-world.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pellman-world.com"] [uri "/bak/wallet.dat"] [unique_id "aYQOkwVv1XxAfTO4ajEs3QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack