๐บ๐ธ
TPI-Abuse
2025-09-26 14:34:30
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 26 10:34:26.242594 2025] [security2:error] [pid 25573:tid 25573] [client 156.253.168.194:36639] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casapapayasanmiguel.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casapapayasanmiguel.com"] [uri "/s3cmd.ini"] [unique_id "aNakclqha8f3Hk81_kKJGQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-11 14:26:40
(9 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-11 13:04:26
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 09:04:21.743420 2025] [security2:error] [pid 7191:tid 7191] [client 156.253.168.194:34855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blogs.melton.space"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMLI1R4LIgNS3FIS4IEPYgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 10:16:42
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 06:16:36.115199 2025] [security2:error] [pid 940:tid 1005] [client 156.253.168.194:58363] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.danelandia.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.danelandia.com"] [uri "/s3cmd.ini"] [unique_id "aLwKBMWyyUvqVWSsY-W_ZAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-05 16:12:19
(9 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-08-31 21:39:13
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 17:39:09.250543 2025] [security2:error] [pid 31135:tid 31135] [client 156.253.168.194:31707] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.batonrougecustomcabinets.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.batonrougecustomcabinets.com"] [uri "/s3cmd.ini"] [unique_id "aLTA_eKohSVoBOVEk_QLJgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-24 08:05:24
(10 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐ง๐ช
cmbplf
2025-08-17 06:20:28
(10 months ago)
5.114 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-08-12 04:32:30
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 12 00:32:24.589135 2025] [security2:error] [pid 12167:tid 12167] [client 156.253.168.194:50937] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJrD2N_1to0dgBShPD2_awAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-28 18:04:37
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 28 14:04:33.589390 2025] [security2:error] [pid 3425513:tid 3425513] [client 156.253.168.194:52633] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lockyers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lockyers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aGAusY8WBeJ3UwVxvZssxAAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-28 12:34:22
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-06-16 20:04:29
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-05-20 15:30:30
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-12-30 05:31:50
(1 year ago)
Attempted brute force login to web vpn 8 time(s); last attempt for 2024.12.30 is noted in report tim ...
show more
Attempted brute force login to web vpn 8 time(s); last attempt for 2024.12.30 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฉ๐ช
nyuuzyou
2024-11-25 08:27:23
(1 year ago)
Intensive scraping: /web?s=%22Trackback%20f%FCr%20spezifische%20URL%20dieses%20Eintrags%22%20kra18.c ...
show more
Intensive scraping: /web?s=%22Trackback%20f%FCr%20spezifische%20URL%20dieses%20Eintrags%22%20kra18.cc%20%D0%B7%D0%B5%D1%80%D0%BA%D0%B0%D0%BB%D0%BE&country=mr-mr&scraper=yandex. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12.5; rv:114.0) Gecko/20100101 Firefox/114.0.
show less
Bad Web Bot