Anonymous
2025-09-29 01:15:10
(8 months ago)
WordPress Brute Force
Brute-Force
Anonymous
2025-09-25 15:47:28
(8 months ago)
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2025-09-25 03:50:56
(8 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 11:06:11
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 07:06:04.229428 2025] [security2:error] [pid 3342575:tid 3342617] [client 154.213.199.164:50977] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kiwimagic.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kiwimagic.net"] [uri "/s3cmd.ini"] [unique_id "aMKtHKU3aFoJY8rHwIPOeAAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 07:48:29
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 03:48:22.790690 2025] [security2:error] [pid 15739:tid 15739] [client 154.213.199.164:22249] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.infinityartistsgroup.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.infinityartistsgroup.com"] [uri "/s3cmd.ini"] [unique_id "aMEtRlNpn4zWaXEBoHq3lwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 12:24:13
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 08:24:05.610184 2025] [security2:error] [pid 5269:tid 5269] [client 154.213.199.164:22495] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.amiance.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.amiance.com"] [uri "/s3cmd.ini"] [unique_id "aL15ZV8ZdE_2BENRNzG5GQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 21:13:40
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 17:13:33.852286 2025] [security2:error] [pid 28984:tid 28984] [client 154.213.199.164:34181] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.depololaw.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.depololaw.com"] [uri "/s3cmd.ini"] [unique_id "aLyj_Y0m-pRLOMuI3qVPJwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 18:23:16
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 14:23:10.081339 2025] [security2:error] [pid 8048:tid 8048] [client 154.213.199.164:17015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.admin.turedinmobiliaria.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLx8DoPMFXfkgKPf7OwrPwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 11:14:26
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.199.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 07:14:19.956409 2025] [security2:error] [pid 13312:tid 13312] [client 154.213.199.164:11747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.digifonics.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLwXixnftu4auQbPV0gWBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2025-09-03 13:44:37
(9 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
HK/Hong Kong/-
Web App Attack
๐ฆ๐บ
weblite
2025-09-01 21:31:21
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ซ๐ท
COMAITE
2025-08-25 15:47:34
(9 months ago)
SQL injection attempt from 154.213.199.164.
Web App Attack
๐ฆ๐บ
weblite
2025-08-18 10:19:39
(10 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2025-08-17 00:44:38
(10 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
HK/Hong Kong/-
Web App Attack
๐ณ๐ฑ
maxxsense
2025-08-14 11:56:49
(10 months ago)
(wordpress) Failed wordpress login from 154.213.199.164 (FR/France/-)
Brute-Force