Anonymous
2026-09-18 05:18:32
(20 hours ago)
ITDATINE WEBEXPLOIT 103.253.27.107 (ip-253-27-107.axgn.com)
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 01:16:47
(1 day ago)
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in t ...
show more
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:16:41.969928 2026] [security2:error] [pid 21882:tid 21882] [client 103.253.27.107:52778] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.jerryfeil.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.jerryfeil.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqyQ9rT2rKreBil0t7Hq3wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
robotstxt
2026-09-17 23:26:22
(1 day ago)
103.253.27.107 - - [17/Sep/2026:23:25:23 +0000] "GET /wp-admin/admin-ajax.php?action=wdpsso_step1&re ...
show more
103.253.27.107 - - [17/Sep/2026:23:25:23 +0000] "GET /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect=&_=1789687522370 HTTP/1.1" 400 11 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15" "-" edge="103.253.27.107"
103.253.27.107 - - [17/Sep/2026:23:25:23 +0000] "GET /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect=&_=1789687522360 HTTP/1.1" 400 11 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:127.0) Gecko/20100101 Firefox/127.0" "-" edge="103.253.27.107"
103.253.27.107 - - [17/Sep/2026:23:25:23 +0000] "GET /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect=&_=1789687522398 HTTP/1.1" 400 11 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-" edge="103.253.27.107"
103.253.27.107 - - [17/Sep/2026:23:25:23 +0000] "GET /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect=&_=1789687522436 HTTP/1.1" 400 11 "-" "Mozilla/5.0 (Windows NT 10.0; Win6
...
show less
Web Spam
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 02:29:49
(3 days ago)
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in t ...
show more
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 22:29:44.684360 2026] [security2:error] [pid 15378:tid 15378] [client 103.253.27.107:60975] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||coolcustomweddingproducts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "coolcustomweddingproducts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqitlbQ3yxq2bsMiryj1BgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-09-15 01:29:26
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: definitelynotahoneypot.online | URI: /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect=&_=1789435766000 | UA: Mozilla/5.0 (X11; Linux x86_64; rv:127.0) Gecko/20100101 Firefox/127.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
πΉπ·
oalver
2026-09-15 00:58:54
(4 days ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect=&_=1788919796676 (HTTP 500); path_signature: request to /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect=&_=1789431357125 (HTTP 400). First seen: 2026-09-09. Risk score: 60/100.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 21:54:35
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in t ...
show more
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:54:30.608979 2026] [security2:error] [pid 27216:tid 27216] [client 103.253.27.107:49838] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.comicpreservation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.comicpreservation.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqhtFCQ6xNpJ0-tI8m60jgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 18:13:17
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in t ...
show more
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 14:13:11.957193 2026] [security2:error] [pid 12070:tid 12070] [client 103.253.27.107:51959] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||cnphilos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cnphilos.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqg5M7-Kvdp45hUpRJ3xPAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 15:28:29
(4 days ago)
COPSLICOM WEBEXPLOIT 103.253.27.107 (ip-253-27-107.axgn.com)
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 15:25:59
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in t ...
show more
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 11:25:53.101732 2026] [security2:error] [pid 25746:tid 25746] [client 103.253.27.107:57169] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||dennisangellismusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dennisangellismusic.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqgR_AiIsEVyNgrJRlzM4gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 12:08:13
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in t ...
show more
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 08:08:06.293641 2026] [security2:error] [pid 838:tid 838] [client 103.253.27.107:50357] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.clayrivers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.clayrivers.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqfjoU5CtbRKWvCd6yzZqAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 10:31:41
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in t ...
show more
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 06:31:36.853351 2026] [security2:error] [pid 17380:tid 17380] [client 103.253.27.107:62527] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "johncyphers.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqfNARyH-2BDTTKOGtIMPgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 09:38:47
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in t ...
show more
(mod_security) mod_security (id:243420) triggered by 103.253.27.107 (ip-253-27-107.axgn.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:38:41.348912 2026] [security2:error] [pid 20942:tid 20942] [client 103.253.27.107:50764] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.circleinthesquare.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.circleinthesquare.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqfAngCB8FO_xtYwq9XvWgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
gigatech
2026-09-11 20:00:04
(1 week ago)
Webserver Probing
Web App Attack
π§π·
Halux
2026-09-11 17:55:47
(1 week ago)
103.253.27.107 Web Application Firewall multiple violations
Hacking
Web App Attack