๐บ๐ธ
TPI-Abuse
2025-10-31 01:37:35
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 21:37:30.128736 2025] [security2:error] [pid 1074:tid 1087] [client 98.159.226.76:48767] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dpscsde.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dpscsde.com"] [uri "/bak/wallet.dat"] [unique_id "aQQS2gluv0ocdxHmDhGBRAAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-24 11:07:46
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 07:07:38.551899 2025] [security2:error] [pid 22656:tid 22656] [client 98.159.226.76:33987] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wendeenicole.com"] [uri "/restore/sftp-config.json"] [unique_id "aPtd-hGhN4tQHCwfffKdxQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-19 15:33:53
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 19 11:33:44.540964 2025] [security2:error] [pid 26509:tid 26509] [client 98.159.226.76:28531] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dudleyanddudley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dudleyanddudley.com"] [uri "/restore/www.sql"] [unique_id "aPUE2IiuZwwXfUV7vmwPJwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2025-10-12 20:17:46
(9 months ago)
Web vulnerability scanning
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-10 18:10:46
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 10 14:10:37.998970 2025] [security2:error] [pid 31388:tid 31388] [client 98.159.226.76:59953] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ccamp.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ccamp.dev"] [uri "/backups/backup.sql"] [unique_id "aOlMHSXSG7GlVeZ8d-WYDQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Thaliruth
2025-10-09 11:48:25
(9 months ago)
98.159.226.76 - - [09/Oct/2025:13:48:23 +0200] "HEAD /backups/directory.tar.gz HTTP/1.1" 301 0 "-" " ...
show more
98.159.226.76 - - [09/Oct/2025:13:48:23 +0200] "HEAD /backups/directory.tar.gz HTTP/1.1" 301 0 "-" "-"
98.159.226.76 - - [09/Oct/2025:13:48:24 +0200] "HEAD /restore/backup.tar.gz HTTP/1.0" 404 3776 "-" "-"
...
show less
Brute-Force
Web App Attack
๐ฏ๐ต
Valhalla
2025-10-09 03:49:49
(9 months ago)
/restore/public_html.gz
Hacking
Web App Attack
๐บ๐ธ
Sylvyon
2025-10-09 02:00:11
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Penny Packer
2025-10-07 05:53:41
(9 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-06 14:56:55
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 06 10:56:50.315512 2025] [security2:error] [pid 10334:tid 10334] [client 98.159.226.76:44375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kim-porter.com"] [uri "/back/sftp-config.json"] [unique_id "aOPYsngRyXDm62ye_dS64gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2025-10-04 06:57:19
(9 months ago)
Web vulnerability scanning
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
S.O.B.A. Dev.
2025-10-04 06:57:16
(9 months ago)
Threat Blocked by BeeHive from (ASN:13213) (Network:UK2NET-AS) (Host:soba.dev) (Method:HEAD) (Protoc ...
show more
Threat Blocked by BeeHive from (ASN:13213) (Network:UK2NET-AS) (Host:soba.dev) (Method:HEAD) (Protocol:HTTP/1.1) (Timestamp:2025-10-04T06:57:16Z)
show less
Web Spam
Brute-Force
Web App Attack
๐ฌ๐ง
pinguin
2025-09-22 22:04:35
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /directory.rar
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-16 18:28:16
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 16 14:28:10.622083 2025] [security2:error] [pid 12558:tid 12558] [client 98.159.226.76:26467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tobyscott.com"] [uri "/backups/sftp-config.json"] [unique_id "aMmsOta9vDP4r9C3YzU6ZQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2025-09-16 01:28:44
(10 months ago)
/backups/application.zip
Hacking
Web App Attack