๐บ๐ธ
mnsf
2026-05-29 12:05:58
(2 weeks ago)
Abuse Detected (2)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 11:40:59
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 07:40:47.849955 2026] [security2:error] [pid 17292:tid 17302] [client 154.6.128.207:33147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.priyom.us"] [uri "/app/config/parameters.yml"] [unique_id "ahl7P2h57-Mngulgnb1rgAAAAMg"], referer: https://www.google.com/search?q=ipv6.priyom.us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 00:27:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 20:27:46.446971 2026] [security2:error] [pid 26709:tid 26709] [client 154.6.128.207:58913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uwsdiving.com"] [uri "/.env.development"] [unique_id "aheMAtzlatx-GDVaZ6RvAgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-27 22:00:49
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-26.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 17:45:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 13:45:44.741476 2026] [security2:error] [pid 29562:tid 29562] [client 154.6.128.207:34263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vaaerobics.vittariadesign.com"] [uri "/.env.production"] [unique_id "ahctyESGMwQfxXEAxBeo-AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-27 13:35:02
(2 weeks ago)
[WedMay2715:34:56.1146402026][security2:error][pid3320035:tid3320812][client154.6.128.207:0]ModSecur ...
show more
[WedMay2715:34:56.1146402026][security2:error][pid3320035:tid3320812][client154.6.128.207:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.filarmonicaagno.ch.81-17-25-250.cpanel.site\"][uri\"/.env.production\"][unique_id\"ahbzAPwoiGCC7n93YKzqdQAAARM\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:58:41
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:58:34.652914 2026] [security2:error] [pid 25332:tid 25332] [client 154.6.128.207:58447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "francisfell.com.themediaplanet.com"] [uri "/.env.backup"] [unique_id "ahZBuv24_-cY7RsvNO4aFgAAAAk"], referer: https://www.google.com/search?q=francisfell.com.themediaplanet.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:21:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:21:16.292077 2026] [security2:error] [pid 26997:tid 26997] [client 154.6.128.207:51163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "board.csems.org"] [uri "/wp-config.php~"] [unique_id "ahY4_BDHy0VV_-p6RaoTVAAAAAM"], referer: https://www.google.com/search?q=board.csems.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 17:11:32
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:11:29.049785 2026] [security2:error] [pid 20315:tid 20315] [client 154.6.128.207:54335] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "railfairofseo.com.powerlinemultimedia.net"] [uri "/wp-config.php.save"] [unique_id "ahXUQXr-BB2ExJe8f49smwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-05-26 14:59:24
(3 weeks ago)
HEAD /.env.production HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-27 02:51:29
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 21:51:24.935302 2026] [security2:error] [pid 1535:tid 1977] [client 154.6.128.207:53711] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.staging.kettlehill.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "staging.kettlehill.com"] [uri "/"] [unique_id "aXgoLLZfoZ-BogEqpvEmTQAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 20:07:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 15:07:08.833239 2026] [security2:error] [pid 14953:tid 14953] [client 154.6.128.207:48861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env"] [unique_id "aWvr7ALXI2mZQWPcQFR0MAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 09:41:07
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:41:01.636410 2025] [security2:error] [pid 17682:tid 17682] [client 154.6.128.207:57513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/wp-content/plugins/wpsite-background-takeover/exports/download.php"] [unique_id "aRWnrbHTrPogthxtqKLYYAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 18:54:25
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 14:53:26.112266 2025] [security2:error] [pid 3221611:tid 3221611] [client 154.6.128.207:33337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.farmers123.com"] [uri "/wp-config.php.original"] [unique_id "aDitJmCpm1tAYhOu81SVlwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-28 02:40:06
(1 year ago)
| SQL injection attempt.
Hacking
SQL Injection
Web App Attack