๐ฉ๐ช
F242
2025-10-06 05:07:49
(8 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-29 19:53:33
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 15:53:30.510624 2025] [security2:error] [pid 6701:tid 6701] [client 156.253.168.123:50337] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pages4you.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pages4you.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aNrjuuDuWGiKrivp4iXrqwAAAB4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2025-09-04 06:35:38
(9 months ago)
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-08-22 15:03:52
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 11:03:46.398933 2025] [security2:error] [pid 17939:tid 17939] [client 156.253.168.123:23791] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kerrywelt.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kerrywelt.com"] [uri "/s3cmd.ini"] [unique_id "aKiG0oRrHEbgi4T8TdwHgAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 10:54:08
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 06:54:01.306648 2025] [security2:error] [pid 2087818:tid 2087853] [client 156.253.168.123:55423] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.harrisonburg.windowtailors.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.harrisonburg.windowtailors.com"] [uri "/s3cmd.ini"] [unique_id "aKhMSR6ohT8yGk8CJc31rAAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 07:33:58
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 03:33:54.972686 2025] [security2:error] [pid 6982:tid 6982] [client 156.253.168.123:48921] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.behrooz.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.behrooz.org"] [uri "/s3cmd.ini"] [unique_id "aKgdYhBp500brUX-uFWzLwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2025-08-18 10:17:23
(10 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2025-08-17 01:06:08
(10 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ZA/South Africa/-
Web App Attack
๐ช๐ธ
el-brujo
2025-07-04 21:22:16
(11 months ago)
Cloudflare WAF: Request Path: / Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (X11; ...
show more
Cloudflare WAF: Request Path: / Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Action: block Source: firewallManaged ASN Description: DREI-K-TECH-GMBH Country: DE Method: GET Timestamp: 2025-07-04T21:22:16Z ruleId: 8e361ee4328f4a3caf6caf3e664ed6fe. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2025-07-04 21:22:15
(11 months ago)
[Fri Jul 04 23:22:14.804134 2025] [proxy_fcgi:error] [pid 72439:tid 73261] [remote 156.253.168.123:0 ...
show more
[Fri Jul 04 23:22:14.804134 2025] [proxy_fcgi:error] [pid 72439:tid 73261] [remote 156.253.168.123:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Fri Jul 04 23:22:15.132621 2025] [proxy_fcgi:error] [pid 72508:tid 73126] [remote 156.253.168.123:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
Anonymous
2025-06-08 00:00:40
(1 year ago)
Fail2ban block
Brute-Force
Web App Attack
Anonymous
2025-06-05 20:20:48
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-05-28 08:58:03
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
oncord
2025-05-03 12:03:03
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
oncord
2025-04-30 18:04:21
(1 year ago)
Form spam
Web Spam