🇬🇧
consul.to
2026-09-12 21:33:06
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
DonAtari
2026-07-05 11:40:55
(2 months ago)
DShield firewall scan - TCP to port 8080
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-06-24 15:14:34
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 151.240.58.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 151.240.58.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 11:14:27.377547 2026] [security2:error] [pid 25167:tid 25167] [client 151.240.58.192:63087] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.copanmaya.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.copanmaya.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajv0U-G4x9l60gjykoj7BAAAAAY"], referer: http://127.0.0.1/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-10 09:32:51
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 05:32:45.547059 2026] [security2:error] [pid 26326:tid 26326] [client 151.240.58.192:52839] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.passy.us|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.passy.us"] [uri "/"] [unique_id "aikvPdTAzfBhgrLr8_TfhwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-10 01:33:22
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 21:33:16.760084 2026] [security2:error] [pid 21377:tid 21436] [client 151.240.58.192:25459] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.dailysavershbg.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.dailysavershbg.com"] [uri "/"] [unique_id "aii-3MvbLNTT9aVxXD_cjwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-09 22:53:41
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 18:53:36.539727 2026] [security2:error] [pid 26804:tid 26804] [client 151.240.58.192:28331] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.kcloot.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.kcloot.com"] [uri "/"] [unique_id "aiiZcJm3bpdJ3iFEw5eOSQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-05-26 18:13:11
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
🇬🇧
consul.to
2026-05-21 03:20:18
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
🇬🇧
consul.to
2026-05-09 00:03:44
(4 months ago)
Web attack/malicious scanning detected
Web App Attack