π©πͺ
Packets-Decreaser.NET
2025-09-15 21:46:40
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-09-11 11:59:49
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 07:59:45.674449 2025] [security2:error] [pid 6866:tid 6866] [client 156.253.172.99:60113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.diselet.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMK5sY6yx3j1aTz3pb7yIwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-11 03:50:28
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 23:50:25.425742 2025] [security2:error] [pid 27339:tid 27339] [client 156.253.172.99:43635] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.buccinet.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.buccinet.com"] [uri "/s3cmd.ini"] [unique_id "aMJHAUS9oodIIrVX0utRAAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-10 14:11:43
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 10:11:38.020119 2025] [security2:error] [pid 20609:tid 20609] [client 156.253.172.99:18101] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.h-mod.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.h-mod.com"] [uri "/s3cmd.ini"] [unique_id "aMGHGpOOpcEUOo0EcxbVzgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-10 13:51:43
(9 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-07 01:56:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 21:56:48.225940 2025] [security2:error] [pid 1617:tid 1617] [client 156.253.172.99:38651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.depthsofsatan.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLzmYGRmXFM1WZs_EBLClQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-06 19:24:55
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 15:24:51.560212 2025] [security2:error] [pid 12029:tid 12029] [client 156.253.172.99:16225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ardecymusic.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLyKgyi_Ep5ljPGTh93upAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-31 22:59:49
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.172.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 18:59:42.458200 2025] [security2:error] [pid 19193:tid 19193] [client 156.253.172.99:11525] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.davefortier.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.davefortier.com"] [uri "/s3cmd.ini"] [unique_id "aLTT3qI9fVz8bwQYJvw5YgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-29 13:08:53
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-08-23 20:33:18
(9 months ago)
wordpress-trap
Web App Attack
Anonymous
2024-12-29 23:59:49
(1 year ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2024.12.29 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2024.12.29 is noted in report timestamp
show less
Hacking
Brute-Force
π¬π§
Steve
2024-12-23 19:00:20
(1 year ago)
Excessive crawling - not obeying robots.txt
Bad Web Bot