๐ฉ๐ช
F242
2025-10-06 03:55:16
(8 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2025-10-03 11:26:11
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-09-26 18:20:11
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-26 15:07:30
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 26 11:07:23.448318 2025] [security2:error] [pid 2067:tid 2067] [client 156.253.174.149:15421] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hyps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hyps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aNasK6DDSSQgxD6oN8_Q1AAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
[email protected]
2025-09-23 00:00:00
(8 months ago)
Form spam attack on aydansfault.net detected on 2025-09-23
Brute-Force
๐ฌ๐ง
[email protected]
2025-09-23 00:00:00
(8 months ago)
Form spam attack on aydansfault.net detected on 2025-09-23
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-08-22 19:10:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 15:10:26.669700 2025] [security2:error] [pid 13935:tid 13935] [client 156.253.174.149:29367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.christine.mathewyoung.com"] [uri "/config.php%7C/.env%7Csettings.py%7C/.yaml%7C/.yml"] [unique_id "aKjAov26ETFvDHLjKqUg8gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 18:10:36
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 14:10:29.069178 2025] [security2:error] [pid 19462:tid 19462] [client 156.253.174.149:31745] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.billhumphreyresearch.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.billhumphreyresearch.com"] [uri "/s3cmd.ini"] [unique_id "aKiylR0n_Y0HaN_nMKCRhgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 06:32:52
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 02:32:47.925513 2025] [security2:error] [pid 3091:tid 3219] [client 156.253.174.149:36781] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kemalinal.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kemalinal.com"] [uri "/s3cmd.ini"] [unique_id "aKgPD9DU6vvwOgQ6s06A5AAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-30 06:24:40
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-13 17:30:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 13 13:30:03.989180 2025] [security2:error] [pid 1260971:tid 1260971] [client 156.253.174.149:56387] [client 156.253.174.149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aticom.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aticom.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aCOBm0BQ_5Gd22fT8YdIXwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-13 16:50:25
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 13 12:50:20.254414 2025] [security2:error] [pid 2117520:tid 2117520] [client 156.253.174.149:36731] [client 156.253.174.149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sparler.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sparler.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aCN4TCZ3YuT4OkvQFB0saAAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-10 06:55:11
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-05-08 00:44:20
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-03 16:25:57
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.174.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 03 12:25:52.941563 2025] [security2:error] [pid 1760159:tid 1760159] [client 156.253.174.149:12509] [client 156.253.174.149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fwa51.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fwa51.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aBZDkDHSfE5fBSzSerp8YQAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack