πΊπΈ
TPI-Abuse
2025-10-02 21:46:44
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.213.197.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.197.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 17:46:40.459441 2025] [security2:error] [pid 16177:tid 16177] [client 154.213.197.102:58675] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marijuanajoint.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marijuanajoint.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aN7ywGtN-lEU_sT8p-sKGQAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-29 21:04:03
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.213.197.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.197.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 17:03:57.281558 2025] [security2:error] [pid 16621:tid 16621] [client 154.213.197.102:24803] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||heinzmail.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "heinzmail.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aNr0PW_z3xIH4n4DkUB82QAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Carsten
2025-08-30 15:55:13
(9 months ago)
GET [index.php?artnr=42&inhalt=news&inhalt=%27]
Port Scan
πΊπΈ
TPI-Abuse
2025-08-22 14:51:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.197.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.197.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 10:50:57.386709 2025] [security2:error] [pid 14547:tid 14547] [client 154.213.197.102:32475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amazingstructural.amazingwelding.com"] [uri "/config.php%7C/.env%7Csettings.py%7C/.yaml%7C/.yml"] [unique_id "aKiD0eyUyBYVKrf5xoze1gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-22 03:31:33
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.197.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.197.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 21 23:31:27.901394 2025] [security2:error] [pid 18586:tid 18586] [client 154.213.197.102:15263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.goldencalculator.riverflow.com"] [uri "/config.php%7C/.env%7Csettings.py%7C/.yaml%7C/.yml"] [unique_id "aKfkj6_mMy0YmojpZfZ9zAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
uhlhosting
2025-08-16 10:33:02
(10 months ago)
conscioussoldiers.com 154.213.197.102 - - [16/Aug/2025:12:33:00.800002 +0200] "GET /wp-admin/plugin- ...
show more
conscioussoldiers.com 154.213.197.102 - - [16/Aug/2025:12:33:00.800002 +0200] "GET /wp-admin/plugin-install.php HTTP/2.0" 403 2491 "-" "-" aKBeXJRkNttJ-wyl8VJLTgAAygM "-" /apache/20250816/20250816-1233/20250816-123300-aKBeXJRkNttJ-wyl8VJLTgAAygM 0 2147 md5:93d8c05d1f104455d1f7811c6ccb04c8
conscioussoldiers.com 154.213.197.102 - - [16/Aug/2025:12:33:01.151966 +0200] "GET /wp-admin/plugin-install.php HTTP/2.0" 403 2491 "-" "-" aKBeXZRkNttJ-wyl8VJLTwAAzwQ "-" /apache/20250816/20250816-1233/20250816-123301-aKBeXZRkNttJ-wyl8VJLTwAAzwQ 0 2145 md5:d81157f300dba2fa8b76b4e8c078260b
conscioussoldiers.com 154.213.197.102 - - [16/Aug/2025:12:33:01.790266 +0200] "GET /wp-admin/plugin-install.php HTTP/2.0" 403 2491 "-" "-" aKBeXZRkNttJ-wyl8VJLUAAAzAw "-" /apache/20250816/20250816-1233/20250816-123301-aKBeXZRkNttJ-wyl8VJLUAAAzAw 0 2145 md5:faa0fd6d4e7b5ab64bd0a1bd23f03bef
conscioussoldiers.com 154.213.197.102 - - [16/Aug/2025:12:33:02.147438 +0200] "GET /wp-admin/plugin-install.php HTTP/2.0" 403 2
...
show less
DDoS Attack
Brute-Force
Anonymous
2025-08-15 17:23:38
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-08-12 06:21:52
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πͺπΈ
10dencehispahard SL
2025-08-07 05:42:28
(10 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
π¦πΊ
oncord
2025-08-01 19:55:09
(10 months ago)
Form spam
Web Spam
π¦πΊ
oncord
2025-07-26 18:58:26
(10 months ago)
Form spam
Web Spam
π¦πΊ
oncord
2025-07-20 08:26:14
(11 months ago)
Form spam
Web Spam
Anonymous
2025-07-19 04:50:21
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π¦πΊ
oncord
2025-07-17 16:11:36
(11 months ago)
Form spam
Web Spam
Anonymous
2025-07-13 19:16:52
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH