๐บ๐ธ
TPI-Abuse
2025-09-11 05:26:03
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 01:25:57.420389 2025] [security2:error] [pid 16546:tid 16546] [client 156.253.169.18:59183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fingerprintinternational.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMJdZSwuh7n5C1W9XiP98AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 18:00:17
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 14:00:13.235058 2025] [security2:error] [pid 6698:tid 6698] [client 156.253.169.18:46873] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.juhoanttila.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.juhoanttila.com"] [uri "/s3cmd.ini"] [unique_id "aMG8rTrh-mqRyC6KiUgShQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 10:23:09
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 06:23:03.739054 2025] [security2:error] [pid 31018:tid 31018] [client 156.253.169.18:20969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.customthanksgivingcards.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aL1dB6OTe__z9ANUhiXWrgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 05:43:34
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 01:43:27.272915 2025] [security2:error] [pid 28881:tid 28903] [client 156.253.169.18:21581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deathconfusion.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLUyf1eZzh3xkShTRF91eAAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 04:30:43
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 00:30:39.244205 2025] [security2:error] [pid 349839:tid 349968] [client 156.253.169.18:27745] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.deutschlandtickets-de.online.djkirby.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.deutschlandtickets-de.online.djkirby.com"] [uri "/s3cmd.ini"] [unique_id "aLUhbwfja2YvriDlTKU24QAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-09-01 03:11:26
(9 months ago)
WP Login Scan Activities
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-08-26 03:58:36
(9 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User A ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User Agent: N/A - Timestamp: 8/26/2025 3:58 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-08-23 01:36:54
(9 months ago)
WP Login Scan Activities
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-08-21 19:20:17
(9 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User A ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User Agent: N/A - Timestamp: 8/21/2025 7:20 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-08-20 08:10:13
(9 months ago)
[Wed Aug 20 10:10:12.575172 2025] [proxy_fcgi:error] [pid 3682246:tid 3682291] [remote 156.253.169.1 ...
show more
[Wed Aug 20 10:10:12.575172 2025] [proxy_fcgi:error] [pid 3682246:tid 3682291] [remote 156.253.169.18:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Wed Aug 20 10:10:13.371650 2025] [proxy_fcgi:error] [pid 3682246:tid 3682280] [remote 156.253.169.18:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
๐ฉ๐ช
conseilgouz
2025-08-16 17:06:32
(9 months ago)
coe-12 : Block return, carriage return, ... characters=>/component/weblinks/weblink/26-joomla-days?I ...
show more
coe-12 : Block return, carriage return, ... characters=>/component/weblinks/weblink/26-joomla-days?Itemid=316&catid=11&catid=%27&task=weblink.go(')
show less
Hacking
๐ช๐ธ
10dencehispahard SL
2025-07-08 07:25:30
(11 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-05-18 16:56:08
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
MAGIC
2025-05-13 01:04:04
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-05-10 21:42:10
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.169.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 10 17:42:02.515358 2025] [security2:error] [pid 1037397:tid 1037397] [client 156.253.169.18:44299] [client 156.253.169.18] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eandgenergy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eandgenergy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aB_IKtv7v_U5keZF44k3CgAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack