Anonymous
2025-10-02 23:33:10
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-26 16:38:30
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 26 12:38:25.020545 2025] [security2:error] [pid 23713:tid 23713] [client 156.228.177.103:51257] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||renjunews.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "renjunews.com"] [uri "/s3cmd.ini"] [unique_id "aNbBgaog9UxJX1I-dF5zJAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 17:34:39
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 13:34:33.571711 2025] [security2:error] [pid 19468:tid 19468] [client 156.228.177.103:32985] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.imabee.andrsn.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMG2qROM9LKsaARuIMDMtQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 10:40:37
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 06:40:34.059327 2025] [security2:error] [pid 430:tid 430] [client 156.228.177.103:57405] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.blog.l3l4.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.blog.l3l4.com"] [uri "/s3cmd.ini"] [unique_id "aMFVol39i1MhPhDiJWdWUAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 10:58:26
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 06:58:20.404664 2025] [security2:error] [pid 1700945:tid 1700965] [client 156.228.177.103:25565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.allstartaxidermy.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aL1lTCvvSeC_R5E4-JnQpgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-09-07 09:07:17
(9 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 156.228.177.103 (DE/Germany/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 156.228.177.103 (DE/Germany/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 07:45:29
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 03:45:24.471200 2025] [security2:error] [pid 28974:tid 28974] [client 156.228.177.103:55481] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.allisonstiles.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.allisonstiles.org"] [uri "/s3cmd.ini"] [unique_id "aLvmlNyXA-f818neK_GKBgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-05 16:40:27
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 05 12:40:23.183873 2025] [security2:error] [pid 15406:tid 15406] [client 156.228.177.103:52907] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.mcarrollcommunications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.mcarrollcommunications.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aLsSd9-pQnJrUrJ9rVpCogAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2025-09-01 21:57:20
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฆ๐บ
weblite
2025-08-18 10:16:32
(10 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2025-08-17 00:42:04
(10 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ZA/South Africa/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-05 00:41:35
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 04 20:41:28.160699 2025] [security2:error] [pid 27348:tid 27348] [client 156.228.177.103:49817] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||miszewski.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "miszewski.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJFTOPl16hv5UvP91rcWVgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-01 11:45:42
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.228.177.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 07:45:37.505896 2025] [security2:error] [pid 23268:tid 23268] [client 156.228.177.103:32217] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||method-one.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "method-one.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aIyo4YTpSVpvhrg5_DIpAQAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2025-07-16 16:39:20
(11 months ago)
MYH: Web Attack GET /wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2025-07-13 16:40:40
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH