Anonymous
2025-09-30 15:07:56
(8 months ago)
XMLRPC Hack Attempts
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-09-10 19:10:35
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 15:10:28.413860 2025] [security2:error] [pid 2220330:tid 2220341] [client 156.253.165.140:41973] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jeflis.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jeflis.com"] [uri "/s3cmd.ini"] [unique_id "aMHNJJ6pEoqK7jMpRgLO6AAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
JimArchon72
2025-09-09 02:17:41
(9 months ago)
2025-09-09 02:17:40 - Port Scan From IP: 156.253.165.140
Port Scan
SSH
๐บ๐ธ
TPI-Abuse
2025-09-07 08:07:57
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 04:07:52.143286 2025] [security2:error] [pid 13056:tid 13056] [client 156.253.165.140:21329] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.antoniorufino.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.antoniorufino.com"] [uri "/s3cmd.ini"] [unique_id "aL09WKYNSpUv93y2vfbGYAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 14:44:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 10:44:01.232057 2025] [security2:error] [pid 31931:tid 31947] [client 156.253.165.140:9299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.catishly.piazza9.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLxIsezWUsBImk8IOCEBBwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-05 17:03:28
(9 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-01 19:00:14
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 15:00:03.626682 2025] [security2:error] [pid 1482:tid 1482] [client 156.253.165.140:51267] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.christineaholtz.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.christineaholtz.com"] [uri "/s3cmd.ini"] [unique_id "aLXtM5ud7dQpozZuQiLHOAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-23 14:19:41
(10 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-08-12 08:05:34
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 12 04:05:29.289463 2025] [security2:error] [pid 11353:tid 11353] [client 156.253.165.140:11631] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gp-cm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gp-cm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJr1yUfCgkRJIySIJqEp6wAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-08-11 07:03:46
(10 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-07-16 15:55:10
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-07-16 05:10:12
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.165.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 16 01:10:09.661527 2025] [security2:error] [pid 5018:tid 5018] [client 156.253.165.140:42219] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chiquy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chiquy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aHc0MXeCHlJfSZa7oTc0_gAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-25 18:53:31
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ช๐ธ
10dencehispahard SL
2025-06-20 05:13:43
(1 year ago)
WP probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
VSM Networks
2025-04-09 21:30:30
(1 year ago)
Credential Stuffing
Brute-Force