πΊπΈ
TPI-Abuse
2026-02-02 05:39:16
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 02 00:39:10.199293 2026] [security2:error] [pid 1316:tid 1316] [client 108.181.121.42:38845] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rendermatrix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rendermatrix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYA4fgjJ8nwDC0IR0vQu1wAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2026-02-02 04:26:06
(4 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-02 03:24:32
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 22:24:24.623405 2026] [security2:error] [pid 26451:tid 26451] [client 108.181.121.42:37471] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flamberge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flamberge.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYAY6HzIYQXcmNYRMc8S5AAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-01 17:05:39
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 12:05:36.670593 2026] [security2:error] [pid 549946:tid 549946] [client 108.181.121.42:37401] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vcmail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vcmail.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aX-H4HK64QYxzWoi6rJKpQAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-01 16:34:25
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 11:34:18.224424 2026] [security2:error] [pid 11046:tid 11046] [client 108.181.121.42:29241] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vjrott.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vjrott.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX-AilOc0fN8YIe8LnYYKQAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
etu brutus
2026-01-29 19:11:04
(4 months ago)
108.181.121.42 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-29 19:03:04
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 14:02:58.216821 2026] [security2:error] [pid 237977:tid 237977] [client 108.181.121.42:18645] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eastbrooktech.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eastbrooktech.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXuu4vHrNEmSXn1pseaKnAAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
geot
2025-09-26 12:32:01
(8 months ago)
GET /wp-content/themes/.git/config HTTP/1.1
GET /wp-content/plugins/.git/config HTTP/1.1
Hacking
Web App Attack
π§πͺ
taivas.nl
2025-09-26 04:32:36
(8 months ago)
Many_bad_calls
Web App Attack
π«π·
geot
2025-09-25 12:16:56
(8 months ago)
GET /irj/go/km/navigation/ HTTP/1.1
GET /sap/admin/public/index.html HTTP/1.1
GET /XMII/Catalog?Mode ...
show more
GET /irj/go/km/navigation/ HTTP/1.1
GET /sap/admin/public/index.html HTTP/1.1
GET /XMII/Catalog?Mode=GetFileList&Path=Classes/../../../../../../../../../../../../etc/passwd HTTP/1.1
GET /sap/bc/BSp/sap/menu/fameset.htm?sap--essioncmd=close&sapexiturl=https%3a%2f%2finteract.sh HTTP/1.1
GET /sap/public/bc/icf/logoff?redirecturl=https://interact.sh HTTP/1.1
show less
Hacking
Bad Web Bot
Web App Attack
πΏπ¦
ITX
2025-09-25 06:12:00
(8 months ago)
Hacking attempts
Hacking
π«π·
LRob.fr
2025-09-25 06:00:17
(8 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2025-09-25 05:46:32
(8 months ago)
Bot / scanning and/or hacking attempts: GET /?order_id=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-ord ...
show more
Bot / scanning and/or hacking attempts: GET /?order_id=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-order_, GET /?edit-menu-item=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-, GET /?activated=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-activ, GET /?next=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-next%27%29, GET /?location=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-locati, GET /?option=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-option%2, GET /?deleted=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-deleted, GET /?i=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-i%27%29%3E&da, GET /?uname=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-uname%27%, GET /?callback=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-callba, GET /?name=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-name%27%29, GET /?t=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-t%27%29%3E&co, GET /?tags=%27%3E%22%3Csvg%2Fonload=confirm%28%27xss-tags%27%29, GET /.git/config HTTP/1.1, GET /wp-content/themes/.git/config HTTP/1.1, GET /wp-content/plugins/.git/config HTTP/1.1
show less
Hacking
Web App Attack
π¬π§
openstrike.co.uk
2025-09-25 05:13:10
(8 months ago)
3 attacks on VC URLs:
GET /wp-content/themes/.git/config HTTP/1.1
Hacking
πΊπΈ
TPI-Abuse
2025-09-25 05:10:11
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.121.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 01:10:03.243423 2025] [security2:error] [pid 28465:tid 28465] [client 108.181.121.42:55928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.portalvasco.com"] [uri "/.git/config"] [unique_id "aNTOq0V1_sMQ3Q9gCRM6bQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack