Anonymous
2025-09-11 22:23:13
(8 months ago)
2025-09-12T00:23:13.367639+02:00 zanati wp(www.sahpa.co.za)[2492421]: Blocked authentication attempt ...
show more
2025-09-12T00:23:13.367639+02:00 zanati wp(www.sahpa.co.za)[2492421]: Blocked authentication attempt for [email protected] from 156.253.167.6
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 10:09:45
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 06:09:40.023316 2025] [security2:error] [pid 4995:tid 4995] [client 156.253.167.6:28397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fairytaleinvitations.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMKf5I7vQEkp8wHFoJ8RYgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 18:21:16
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 14:21:10.107575 2025] [security2:error] [pid 29558:tid 29558] [client 156.253.167.6:59777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.example.directnic-support.rocks"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMHBloh8rQImJfuw99uZvAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 07:58:33
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 03:58:25.136791 2025] [security2:error] [pid 13492:tid 13492] [client 156.253.167.6:38849] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.carterrose.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.carterrose.com"] [uri "/s3cmd.ini"] [unique_id "aLvpoYRjJGSKl9p4ZzPbNQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-02 12:53:28
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-08-31 23:54:55
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 19:54:49.474261 2025] [security2:error] [pid 21615:tid 21634] [client 156.253.167.6:46887] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.clientes.despachosyoficinas.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.clientes.despachosyoficinas.com"] [uri "/s3cmd.ini"] [unique_id "aLTgyfI5uIJ-bkPNazw9EwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-29 17:21:40
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-12 17:49:02
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 12 13:48:57.450259 2025] [security2:error] [pid 538335:tid 538335] [client 156.253.167.6:32575] [client 156.253.167.6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||herrell.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "herrell.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aCI0iSDPDT9y7a7bPPI6pQAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-16 22:46:29
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 16 18:46:21.905463 2025] [security2:error] [pid 23025:tid 23025] [client 156.253.167.6:32837] [client 156.253.167.6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||henryweb.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "henryweb.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aAAzPanmnjMmynHhDrhimQAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-16 19:38:55
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 16 15:38:49.127591 2025] [security2:error] [pid 2241023:tid 2241023] [client 156.253.167.6:15483] [client 156.253.167.6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flugstad.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flugstad.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aAAHSTnD_fnB32yGO7RybwAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-15 03:13:07
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
nowyouknow
2025-04-14 14:58:57
(1 year ago)
(From [email protected] ) Hi,
Do you offer a referral program to sell the products on you ...
show more
(From [email protected] ) Hi,
Do you offer a referral program to sell the products on your website?
I recently worked on a similar product offer with success and have gained a database of individuals who I believe would be interested in your products. I hoped to sign up with you to earn a commission for each person I refer who buys from your website.
I would be keen to promote your products to my database, but you would need to provide me with a unique affiliate link to ensure that the sales I generate through your site are tracked and attributed to me.
No upfront marketing fees, and I am willing to be compensated on a conversion or sale basis only, which most online vendors appreciate.
I am not very technical, so if you do not currently offer anything like this, I would not be able to assist you. I am primarily an email and social media marketer, but I notice that your site is built on WordPress, and you can hire a freelancer to set this up for about $100, or possibly even less.
An
show less
Phishing
Web Spam
๐ฆ๐บ
oncord
2025-04-05 21:13:24
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
oncord
2025-04-04 17:10:13
(1 year ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2025-04-02 03:16:56
(1 year ago)
Form spam
Web Spam