๐ฆ๐บ
paulshipley.com.au
2026-09-17 08:46:15
(1 week ago)
[Thu Sep 17 18:46:15.058806 2026] [security2:error] [pid 492526] [client 155.212.37.143:11709] [clie ...
show more
[Thu Sep 17 18:46:15.058806 2026] [security2:error] [pid 492526] [client 155.212.37.143:11709] [client 155.212.37.143] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellagiftware.com.au"] [uri "/robots.txt"] [unique_id "aquo14gHLZ0tufgvnwe87gAAAAM"]
...
show less
Web App Attack
๐ฉ๐ช
4server
2026-09-11 02:25:50
(2 weeks ago)
[FriSep1104:25:46.3206232026][security2:error][pid1097510:tid1097607][client155.212.37.143:0]ModSecu ...
show more
[FriSep1104:25:46.3206232026][security2:error][pid1097510:tid1097607][client155.212.37.143:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"maxay.ch\"][uri\"/xmlrpc.php\"][unique_id\"aqNmqjBQh0u6m1oLiFWQzgAAAgk\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
Mike Stevenson
2026-08-04 05:40:10
(1 month ago)
Blog Spam
๐บ๐ธ
TPI-Abuse
2026-07-28 01:06:09
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 21:06:02.742424 2026] [security2:error] [pid 941094:tid 941094] [client 155.212.37.143:27135] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barnesandbrower.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barnesandbrower.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amgAeqHNoAVgADi3a4oKLwAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-23 14:45:28
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-10 10:05:39
(2 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-05-26 15:36:01
(3 months ago)
Known malicious PHP file or CMS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 20:32:30
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 16:32:25.363178 2026] [security2:error] [pid 7068:tid 7068] [client 155.212.37.143:52975] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||impostersyndromeunmasked.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "impostersyndromeunmasked.com"] [uri "/"] [unique_id "afew2RLQLV3K7Cf1q7yTKQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-04-13 01:12:00
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-05 09:27:02
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 05:26:55.661991 2026] [security2:error] [pid 8370:tid 8370] [client 155.212.37.143:20611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jkperis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jkperis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adIq3__8M3z4XSslZ6usuQAAABQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 19:27:04
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 15:26:58.364161 2026] [security2:error] [pid 11958:tid 11958] [client 155.212.37.143:49609] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||unitedletter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "unitedletter.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adAUgt7YsHNE7ZkWP9jaGAAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 09:22:12
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 155.212.37.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 05:22:06.473647 2026] [security2:error] [pid 7080:tid 7080] [client 155.212.37.143:27955] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pourier.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pourier.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ac-Gvk3oDfD9DExNlPx9SgAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-28 17:48:43
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack