Anonymous
2025-10-02 04:31:53
(8 months ago)
Failed login attempt detected by Fail2Ban in recidive jail
Brute-Force
๐จ๐ญ
backslash
2025-09-12 03:20:23
(8 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-07 03:36:29
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 23:36:21.913633 2025] [security2:error] [pid 21906:tid 21906] [client 156.253.166.225:44205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ic1.ic1.biz"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLz9tUa6-n0WqVaiDJYKHAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-05 23:40:46
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 05 19:40:42.273664 2025] [security2:error] [pid 9324:tid 9324] [client 156.253.166.225:34461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jessicabaer.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLt0-mInj5UfxXSMyuV6WwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2025-09-02 02:18:46
(9 months ago)
(From [email protected] )
Aiming to energize your websiteโs reach? Our intelligent AI system ...
show more
(From [email protected] )
Aiming to energize your websiteโs reach? Our intelligent AI system pulls perfect visitors using keywords and place-based precision from continents to local areas.
Wanting increased revenue, active website traffic, or expanded web impact?
We adjust it to fit your goals. Enjoy a 7-day free trial period with no contract. Dive in here:
https://ow.ly/bBOa50WOcRC
show less
Phishing
Web Spam
๐ฆ๐บ
oncord
2025-09-02 02:15:07
(9 months ago)
Form spam
Web Spam
๐ฆ๐บ
weblite
2025-09-01 21:42:50
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 06:04:53
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 02:04:45.903740 2025] [security2:error] [pid 19923:tid 19923] [client 156.253.166.225:24561] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.emisoni.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.emisoni.com"] [uri "/s3cmd.ini"] [unique_id "aLU3fWYnR9aZKRMd5n0bJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 04:59:50
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 00:59:45.199270 2025] [security2:error] [pid 26975:tid 26975] [client 156.253.166.225:59393] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.epk.gmacguffin.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.epk.gmacguffin.com"] [uri "/s3cmd.ini"] [unique_id "aLUoQSxd4wxndm89_ujnYAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 04:15:37
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.166.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 00:15:32.359176 2025] [security2:error] [pid 29943:tid 29943] [client 156.253.166.225:12299] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.english.art.mavikalem.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.english.art.mavikalem.org"] [uri "/s3cmd.ini"] [unique_id "aLUd5FiDLA7HRh-yQpiXBwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2025-08-31 20:16:36
(9 months ago)
(From [email protected] )
Facing low website engagement? Our AI platform delivers perfect visit ...
show more
(From [email protected] )
Facing low website engagement? Our AI platform delivers perfect visitors through keywords and geographic focus from global regions to neighborhoods.
Looking for increased revenue, active website traffic, or a broader online footprint?
We tailor it to suit your vision. Enjoy a 7-day free trial period with no contract. Join now:
https://ow.ly/mEoo50WOcQC
show less
Phishing
Web Spam
๐ฉ๐ช
Ba-Yu
2025-08-23 18:41:31
(9 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐ฆ๐บ
weblite
2025-08-18 10:22:39
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฆ๐บ
oncord
2025-08-17 18:23:58
(9 months ago)
Form spam
Web Spam
๐ฆ๐บ
screwlooseit.com.au
2025-08-17 01:03:23
(9 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ZA/South Africa/-
Web App Attack