๐บ๐ธ
TPI-Abuse
2026-06-21 00:48:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 20:48:46.296037 2026] [security2:error] [pid 18668:tid 18668] [client 158.173.241.123:61005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dbfitwell.com"] [uri "/wp-config.php.bak"] [unique_id "ajc07gfB08ELnZlqMoPstwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 07:19:45
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 03:19:43.003064 2026] [security2:error] [pid 24402:tid 24412] [client 158.173.241.123:31893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cjherbalremedies.com"] [uri "/wp-config.php.bak"] [unique_id "ajY_D9EKUtUDMjYHSu3n_gAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 21:54:27
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 17:54:21.426970 2026] [security2:error] [pid 18881:tid 18889] [client 158.173.241.123:32175] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaoticperception.com"] [uri "/wp-config.php.bak"] [unique_id "ajW6jZ4aqVE8PMBsgdpvuQAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-19 12:05:14
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 11:20:34
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 07:20:27.727734 2026] [security2:error] [pid 4095:tid 4095] [client 158.173.241.123:23713] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brbcar.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brbcar.com"] [uri "/wp-config.php.bak"] [unique_id "ajUl-8B58ahUbiFaQJ9MCgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 04:54:22
(3 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 07:19:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 03:19:21.214977 2026] [security2:error] [pid 12708:tid 12708] [client 158.173.241.123:22515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thepinman.org"] [uri "/wp-config.php.bak"] [unique_id "ahVJeaZKY_OV0ei577xyogAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-05-20 19:23:19
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
nowyouknow
2026-05-19 23:38:37
(3 months ago)
(From [email protected] ) URGENT! Take the Reigns with Your 1.3426 BTC https://1borsa.com/aw46u ...
show more
(From [email protected] ) URGENT! Take the Reigns with Your 1.3426 BTC https://1borsa.com/aw46u
TAG: x3fg2t2b7k2x1d6lh5ra6s6s8a1t3f9px5xj1x7s5i1i0i7ml9fb1c6o4p8e3y8cd5xx4o6l9x1r1h5sa6nx1x1a5r8z7m5ak8ie9m7j1e7d3s4n
show less
Phishing
Web Spam
๐บ๐ธ
tropicalidad.be
2026-05-19 23:26:22
(3 months ago)
blog spam/exploit attempt
Blog Spam
Hacking
๐ฆ๐บ
oncord
2026-05-19 19:04:03
(3 months ago)
Form spam
Web Spam
๐ณ๐ฑ
Libra
2026-05-19 17:36:59
(3 months ago)
Fail2ban jail=wordpress-guestbook increase=1
Web Spam
๐ฉ๐ช
big-cloud.nl
2026-05-04 09:54:12
(4 months ago)
Try to access /xmlrpc.php
Web App Attack
๐ฉ๐ช
4server
2026-05-04 06:47:56
(4 months ago)
[MonMay0408:47:51.4883982026][security2:error][pid4036660:tid4036764][client158.173.241.123:0]ModSec ...
show more
[MonMay0408:47:51.4883982026][security2:error][pid4036660:tid4036764][client158.173.241.123:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"giftech.ch\"][uri\"/xmlrpc.php\"][unique_id\"afhBF8xD5z-ATxYqa0SKpQAAAQU\"]\,referer:https://giftech.ch/xmlrpc.php
show less
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-04-25 09:39:51
(4 months ago)
Web attack/malicious scanning detected
Web App Attack