๐บ๐ธ
TPI-Abuse
2025-09-11 12:47:56
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 08:47:52.393761 2025] [security2:error] [pid 3313385:tid 3313404] [client 156.253.176.49:23053] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.econpage.ahsdistance.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.econpage.ahsdistance.org"] [uri "/s3cmd.ini"] [unique_id "aMLE-F7yv2vPZpMZmgMSjwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 00:50:21
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 20:50:16.104966 2025] [security2:error] [pid 1908:tid 1908] [client 156.253.176.49:54875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.guitarsouth.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMIcyGlqv6RH_s0wDNFFvwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 07:01:11
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 03:01:07.117042 2025] [security2:error] [pid 13810:tid 13810] [client 156.253.176.49:19691] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.businessgetwellcards.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.businessgetwellcards.com"] [uri "/s3cmd.ini"] [unique_id "aL0ts2Kl_MUA_WZ2U8Bp0QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 04:57:13
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 00:57:05.921299 2025] [security2:error] [pid 29647:tid 29647] [client 156.253.176.49:21881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cspminc.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aL0QoRRf_TSCt3oI1NcS8wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 02:30:03
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 22:29:55.327498 2025] [security2:error] [pid 6764:tid 6884] [client 156.253.176.49:27135] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.apic.kylight.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.apic.kylight.com"] [uri "/s3cmd.ini"] [unique_id "aLzuI52s0hbERGZZN-V9zwAAAcs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-08-11 07:08:21
(10 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-08-04 22:50:24
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.176.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 04 18:50:17.961593 2025] [security2:error] [pid 7143:tid 7143] [client 156.253.176.49:45201] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||behrooz.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "behrooz.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aJE5KaUEI8aIwx6Cl49H8wAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-04 11:46:21
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
nowyouknow
2025-08-03 04:11:07
(10 months ago)
Malicious Traffic/Form Submission
Phishing
Web Spam
๐ฆ๐บ
oncord
2025-08-02 09:12:54
(10 months ago)
Form spam
Web Spam
๐บ๐ธ
nowyouknow
2025-07-23 02:48:11
(10 months ago)
(From [email protected] ) This is an open job position to be a website chat assistant. We current ...
show more
(From [email protected] ) This is an open job position to be a website chat assistant. We currently have lots of different businesses hiring for these positions in all countries right now. Website chat assistants are the people who answer the customerโs live chat support or sales questions on a businessโs website. The work is done online, normally from home. Read the full details here to complete your application if you are interested.
-----> https://bit.ly/3GI4OZ0
show less
Phishing
Web Spam
Anonymous
2025-06-29 11:30:16
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
oncord
2025-06-27 00:54:53
(11 months ago)
Form spam
Web Spam
๐บ๐ธ
nowyouknow
2025-06-22 16:20:42
(11 months ago)
(From [email protected] ) This is an open job position to be a website chat assistant. We cu ...
show more
(From [email protected] ) This is an open job position to be a website chat assistant. We currently have lots of different businesses hiring for these positions in all countries right now. Website chat assistants are the people who answer the customerโs live chat support or sales questions on a businessโs website. The work is done online, normally from home. Read the full details here to complete your application if you are interested.
-----> https://bit.ly/3GI4OZ0
show less
Phishing
Web Spam
Anonymous
2025-05-17 16:09:21
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH