Anonymous
2025-09-27 19:48:05
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
🇺🇸
TPI-Abuse
2025-09-11 02:03:26
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 22:03:19.347502 2025] [security2:error] [pid 26602:tid 26602] [client 156.253.179.7:53453] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanexportimport.internetnameregistration.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanexportimport.internetnameregistration.com"] [uri "/s3cmd.ini"] [unique_id "aMIt5zYUkfAGkA95Nsht1gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-07 03:18:46
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 23:18:41.953425 2025] [security2:error] [pid 6764:tid 6895] [client 156.253.179.7:40013] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cheqs.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cheqs.org"] [uri "/s3cmd.ini"] [unique_id "aLz5kZ2s0hbERGZZN-WSlwAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-07 02:41:39
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 22:41:32.298784 2025] [security2:error] [pid 11767:tid 11767] [client 156.253.179.7:27191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wwwhold.bccworldmedia.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLzw3EhH3yJrMrR3pxWhUAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-06 23:55:13
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 19:55:08.499812 2025] [security2:error] [pid 7187:tid 7187] [client 156.253.179.7:54957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.danharrisphotoart.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLzJ3Ib1h-nM-CZ1uXHtVgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-06 11:51:17
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 07:51:12.231519 2025] [security2:error] [pid 6520:tid 6520] [client 156.253.179.7:47333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bletnslb.org"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLwgMLDFDcwpdBspdNu-jgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-01 19:53:18
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.179.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 15:53:13.387103 2025] [security2:error] [pid 4446:tid 4446] [client 156.253.179.7:45279] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.engedal.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.engedal.net"] [uri "/s3cmd.ini"] [unique_id "aLX5qZQ9Og4hSqdEkBV4pgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nowyouknow
2025-08-15 17:41:12
(1 year ago)
Malicious Traffic/Form Submission
Phishing
Web Spam
🇦🇺
oncord
2025-07-31 12:58:06
(1 year ago)
Form spam
Web Spam
🇫🇷
sterile.network
2025-07-29 18:22:51
(1 year ago)
Emulator: rdp
Port: 3389
Commands: 1025
Caught on server-1 using StickyPorts!
https://github.com ...
show more
Emulator: rdp
Port: 3389
Commands: 1025
Caught on server-1 using StickyPorts!
https://github.com/ImInTheICU/sticky-ports
show less
Port Scan
Hacking
Brute-Force
🇺🇸
nowyouknow
2025-07-24 15:36:50
(1 year ago)
(From [email protected] ) This is an open job position to be a website chat assistant. We curre ...
show more
(From [email protected] ) This is an open job position to be a website chat assistant. We currently have lots of different businesses hiring for these positions in all countries right now. Website chat assistants are the people who answer the customer’s live chat support or sales questions on a business’s website. The work is done online, normally from home. Read the full details here to complete your application if you are interested.
-----> https://bit.ly/3GI4OZ0
show less
Phishing
Web Spam
Anonymous
2025-07-24 13:11:52
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
🇺🇸
nowyouknow
2025-07-16 10:27:14
(1 year ago)
(From [email protected] ) This is an open job position to be a website chat assistant. ...
show more
(From [email protected] ) This is an open job position to be a website chat assistant. We currently have lots of different businesses hiring for these positions in all countries right now. Website chat assistants are the people who answer the customer’s live chat support or sales questions on a business’s website. The work is done online, normally from home. Read the full details here to complete your application if you are interested.
-----> https://bit.ly/3GI4OZ0
show less
Phishing
Web Spam
🇺🇸
nowyouknow
2025-07-02 23:22:02
(1 year ago)
(From [email protected] ) This is an open job position to be a website chat assistant. We currently ...
show more
(From [email protected] ) This is an open job position to be a website chat assistant. We currently have lots of different businesses hiring for these positions in all countries right now. Website chat assistants are the people who answer the customer’s live chat support or sales questions on a business’s website. The work is done online, normally from home. Read the full details here to complete your application if you are interested.
-----> https://bit.ly/3GI4OZ0
show less
Phishing
Web Spam
Anonymous
2025-07-01 23:04:53
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH