๐ณ๐ฑ
Mangelot Hosting
2025-10-05 03:58:39
(8 months ago)
(bad_user_agent) srv103 Bad User-Agent 156.253.171.193 (GB/United Kingdom/-): 10 in the last 3600 se ...
show more
(bad_user_agent) srv103 Bad User-Agent 156.253.171.193 (GB/United Kingdom/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
Marc
2025-10-05 00:43:17
(8 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
WeekendWeb
2025-10-04 13:25:52
(8 months ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-02 23:23:46
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 19:23:41.435017 2025] [security2:error] [pid 26580:tid 26580] [client 156.253.171.193:37221] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pseudospace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pseudospace.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aN8JfR4C7aurFSwUC4sTZAAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-30 05:53:11
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 30 01:53:04.801827 2025] [security2:error] [pid 24722:tid 24722] [client 156.253.171.193:9319] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||monopolimusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "monopolimusic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aNtwQNZ6uAfXId-G9BHq5QAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-29 01:59:14
(8 months ago)
WordPress Brute Force
Brute-Force
๐ซ๐ท
dynamix
2025-09-28 23:30:13
(8 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2025-09-27 10:48:47
(8 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ฎ
YF
2025-09-27 03:01:27
(8 months ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
๐ฉ๐ช
applemooz
2025-09-27 00:04:55
(9 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2025-09-12 01:16:50
(9 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 08:26:29
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 04:26:26.365651 2025] [security2:error] [pid 5798:tid 5798] [client 156.253.171.193:13727] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kiubo.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kiubo.net"] [uri "/s3cmd.ini"] [unique_id "aMKHsgwAZDz_Ohc2h5kNXAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-09-09 15:04:05
(9 months ago)
6.034 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-07 08:34:49
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 04:34:42.533808 2025] [security2:error] [pid 9942:tid 9942] [client 156.253.171.193:37325] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.customprintedweddingnapkins.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.customprintedweddingnapkins.com"] [uri "/s3cmd.ini"] [unique_id "aL1Dona0a92Pao3-GcC9PQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 03:13:20
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.171.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 23:13:14.453161 2025] [security2:error] [pid 24558:tid 24558] [client 156.253.171.193:38775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jamworldmovements.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLz4SsD78NlPNTM0qdEvtwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack