๐บ๐ธ
TPI-Abuse
2026-07-25 01:51:46
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 21:51:40.138945 2026] [security2:error] [pid 3676029:tid 3676029] [client 139.59.156.202:54235] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||pluralmatrix.net|F|2"] [data ".net.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pluralmatrix.net"] [uri "/pluralmatrix.net.bak"] [unique_id "amQWrBLY1DP_Qnut6zj_pAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-07-13 20:15:02
(1 week ago)
WordPress brute force
Brute-Force
๐ช๐ธ
alferez
2026-07-12 21:56:17
(1 week ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 03:30:59
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 23:30:53.176973 2026] [security2:error] [pid 27244:tid 27244] [client 139.59.156.202:37127] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lunchtimers.org|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lunchtimers.org"] [uri "/wwwroot.bak"] [unique_id "aj9D7U_tpIhKJO_V-OiixgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 12:47:14
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 08:47:10.835064 2026] [security2:error] [pid 24357:tid 24357] [client 139.59.156.202:59417] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||copiersgreensboro.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "copiersgreensboro.com"] [uri "/public_html.bak"] [unique_id "ajU6TnuVG0RyBoTWpgyRWwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 11:31:46
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 07:31:39.965218 2026] [security2:error] [pid 13918:tid 13918] [client 139.59.156.202:60697] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pluscures.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pluscures.com"] [uri "/pluscures_com.bak"] [unique_id "ai_im0FuBF0tWezQAwZtjwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 02:16:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 22:16:08.684635 2026] [security2:error] [pid 29079:tid 29079] [client 139.59.156.202:37142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karenjoyce.com"] [uri "/.env"] [unique_id "aitr6B75jr0wmkAodL68swAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-11 11:02:30
(1 month ago)
[ThuJun1113:02:27.5120382026][security2:error][pid1929529:tid1929638][client139.59.156.202:0]ModSecu ...
show more
[ThuJun1113:02:27.5120382026][security2:error][pid1929529:tid1929638][client139.59.156.202:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"ggarchitetti.ch\"][uri\"/cgi-bin.bak\"][unique_id\"aiqVw0F2En6YKXQ0PIAh4QAAAQU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 21:59:58
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:59:54.860614 2026] [security2:error] [pid 25724:tid 25724] [client 139.59.156.202:36723] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brianknudsen.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brianknudsen.com"] [uri "/123456.bak"] [unique_id "aic7WgL-L3D4_B77k7O2jgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 23:53:32
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 19:53:29.221645 2026] [security2:error] [pid 24208:tid 24208] [client 139.59.156.202:50862] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||krmartindale.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "krmartindale.com"] [uri "/2024.bak"] [unique_id "aheD-SOCLpsJzPsV-lNnVwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-05-23 05:20:12
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-03-22 07:45:27
(4 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-03-16 14:50:12
(4 months ago)
(mod_security) mod_security (id:949110) triggered by 139.59.156.202 (DE/Germany/-): N in the last X ...
show more
(mod_security) mod_security (id:949110) triggered by 139.59.156.202 (DE/Germany/-): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 23:07:34
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 139.59.156.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 18:07:29.804219 2026] [security2:error] [pid 1790:tid 1790] [client 139.59.156.202:34440] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||berklie.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "berklie.com"] [uri "/wp.bak"] [unique_id "aadpsbfnPpSsiZB8VpBeWgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2026-02-24 20:11:44
(5 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force