๐ง๐ช
voormedia
2025-09-15 23:44:36
(9 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-15 04:04:49
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-09-12 06:57:49
(9 months ago)
WordPress Brute Force
Brute-Force
๐บ๐ธ
myagent.site
2025-09-06 12:48:38
(9 months ago)
Blocking for trying to access an exploit file: http://amazingdaviehomes.com:80/xmlrpc.php?rsd
Hacking
๐บ๐ธ
TPI-Abuse
2025-08-22 17:50:39
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 13:50:31.928295 2025] [security2:error] [pid 1729:tid 1729] [client 156.253.168.185:58779] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jacob.bluegrassexpressband.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jacob.bluegrassexpressband.com"] [uri "/s3cmd.ini"] [unique_id "aKit5-lmHLaLoAR82kFs7AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 07:33:25
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 03:33:17.954017 2025] [security2:error] [pid 32680:tid 32680] [client 156.253.168.185:45831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flinthillsveterans.org"] [uri "/config.php%7C/.env%7Csettings.py%7C/.yaml%7C/.yml"] [unique_id "aKgdPdMoKFVU9G9d0Uy7pgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 02:28:36
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 21 22:28:30.774270 2025] [security2:error] [pid 1475016:tid 1475158] [client 156.253.168.185:49853] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.koalacogs.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.koalacogs.com"] [uri "/s3cmd.ini"] [unique_id "aKfVzj9MbZcFXbyNn85sqgAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-18 07:01:00
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 18 03:00:56.566713 2025] [security2:error] [pid 30418:tid 30418] [client 156.253.168.185:19609] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||36hoursonly.vittariadesign.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "36hoursonly.vittariadesign.com"] [uri "/s3cmd.ini"] [unique_id "aKLPqHJNeHyXkWe4cQcoywAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-09 19:27:38
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 09 15:27:33.980244 2025] [security2:error] [pid 2396:tid 2396] [client 156.253.168.185:44075] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJehJWXqEhFLed2jBQjq_AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-27 15:49:12
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-07-19 03:55:08
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-07-16 14:16:12
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 16 10:16:09.141992 2025] [security2:error] [pid 1232:tid 1232] [client 156.253.168.185:20303] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.geodogs.org:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.geodogs.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aHe0KVmPxHoWHerRzd-MCQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-30 12:00:59
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-06-15 23:46:53
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-13 02:52:43
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH