๐บ๐ธ
TPI-Abuse
2026-05-28 00:55:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 20:55:09.624629 2026] [security2:error] [pid 10327:tid 10327] [client 154.6.127.211:49619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lisadodd.com"] [uri "/.env.development"] [unique_id "aheSbTWErZgFcw8UO-DbigAAABQ"], referer: https://www.google.com/search?q=lisadodd.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-27 23:22:19
(1 week ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 154.6.127.211 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 154.6.127.211 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-27 22:00:34
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-26.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 12:38:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 08:38:03.632783 2026] [security2:error] [pid 16404:tid 16404] [client 154.6.127.211:59903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.meridianranchdrc.org"] [uri "/wp-config.php.swp"] [unique_id "ahblqwrXOyHEEn14hkVSrwAAAAs"], referer: https://www.google.com/search?q=cpcalendars.meridianranchdrc.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:22:23
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:22:14.132548 2026] [security2:error] [pid 1339:tid 1339] [client 154.6.127.211:53601] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vsecuritysolutions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vsecuritysolutions.com"] [uri "/db_backup.sql"] [unique_id "ahY5NkDErlnzx9rsKG1EYQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-26 21:59:08
(1 week ago)
Auto-ban: >3000 req/min op 2026-05-26
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-26 18:07:40
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 14:07:31.409486 2026] [security2:error] [pid 12949:tid 12949] [client 154.6.127.211:45467] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thomasandross.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thomasandross.com"] [uri "/backup.sql"] [unique_id "ahXhYydmeRUgckFW5WNefwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 16:27:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 12:27:19.450486 2026] [security2:error] [pid 18082:tid 18082] [client 154.6.127.211:38763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "needtoorder.us"] [uri "/.env.local"] [unique_id "ahXJ59rjpGpeyJS2ITP9NwAAAAo"], referer: https://www.google.com/search?q=needtoorder.us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 17:11:16
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 12:11:06.555880 2026] [security2:error] [pid 19643:tid 19643] [client 154.6.127.211:54935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.dev.local"] [unique_id "aWvCqshOocYy34v5-sgmXQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 19:06:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:06:41.396354 2025] [security2:error] [pid 31734:tid 31743] [client 154.6.127.211:58093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/.htaccess"] [unique_id "aVLRQWCDVM70TD0LIjvRHQAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 11:52:23
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 06:52:15.618783 2025] [security2:error] [pid 14877:tid 14877] [client 154.6.127.211:55947] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ftp.nbcnewsradio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ftp.nbcnewsradio.com"] [uri "/mcp"] [unique_id "aRXGbzGM8iTYx6uhPlbKbAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:57:15
(10 months ago)
(mod_security) mod_security (id:221260) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:56:58.661633 2025] [security2:error] [pid 404370:tid 404576] [client 154.6.127.211:37413] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||whm.staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.staging.kettlehill.com"] [uri "/debug.cgi"] [unique_id "aIV5Wsy-cZtwxEkIWL85IQAAANc"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 20:39:17
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.127.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 16:39:07.580066 2025] [security2:error] [pid 3465272:tid 3465272] [client 154.6.127.211:42163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.farmers123.com"] [uri "/.env.development.local"] [unique_id "aDjF61cYClomX1SC-7jcrAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-15 06:10:20
(1 year ago)
| XSS (Cross Site Scripting) attempt.
Hacking
SQL Injection
Web App Attack