๐บ๐ธ
TPI-Abuse
2026-06-03 19:55:12
(1 day ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 15:55:07.988083 2026] [security2:error] [pid 9201:tid 9237] [client 158.173.241.147:46505] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||selfhelpbook.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "selfhelpbook.org"] [uri "/license.txt"] [unique_id "aiCGm4EULaIyTs2yQm2O6gAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 12:10:50
(1 day ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 08:10:47.156950 2026] [security2:error] [pid 5025:tid 5025] [client 158.173.241.147:65061] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||mvscouts.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "mvscouts.org"] [uri "/license.txt"] [unique_id "aiAZx1mHQWYrQ67c9RtZ1AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 05:57:41
(1 day ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:57:34.274136 2026] [security2:error] [pid 13383:tid 13383] [client 158.173.241.147:43469] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.kriske.com|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.kriske.com"] [uri "/license.txt"] [unique_id "ah_CTvq7olcFx8J4Nt7nNQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 05:03:40
(1 day ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:03:34.740149 2026] [security2:error] [pid 11891:tid 11932] [client 158.173.241.147:36453] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||linfoulk.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "linfoulk.org"] [uri "/license.txt"] [unique_id "ah-1pozZD7QPWvFjDvhmvgAAAZM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 04:44:38
(1 day ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 00:44:31.279159 2026] [security2:error] [pid 18016:tid 18016] [client 158.173.241.147:21031] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||texassportsmansassociation.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "texassportsmansassociation.org"] [uri "/license.txt"] [unique_id "ah-xL55W5VAo3fWAwOK6dgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 03:21:19
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 23:21:15.094889 2026] [security2:error] [pid 17847:tid 17847] [client 158.173.241.147:25289] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||cuetzpalin.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "cuetzpalin.org"] [uri "/license.txt"] [unique_id "ah-dq11v9GJUTcoZyJcGEgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-06-02 23:32:31
(2 days ago)
WP Config Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 10:39:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:39:44.756248 2026] [security2:error] [pid 16719:tid 16719] [client 158.173.241.147:41845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "argcreativegroup.com"] [uri "/wp-config.php.bak"] [unique_id "ah6y8K71KBDeORnNy2tdGAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 15:59:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 11:59:22.777557 2026] [security2:error] [pid 870:tid 870] [client 158.173.241.147:40663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abundancecompany.com"] [uri "/wp-config.php.bak"] [unique_id "ah2sWljBXv9M7dStqDa7xQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-01 13:07:55
(3 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-06-01 00:55:34
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 14:31:18
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 10:31:12.857815 2026] [security2:error] [pid 16750:tid 16750] [client 158.173.241.147:30197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drdot.xyz"] [uri "/wp-config.php.bak"] [unique_id "ahr0sEV5jeph6GIHvP9ThAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 19:05:33
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 15:05:29.949547 2026] [security2:error] [pid 21012:tid 21012] [client 158.173.241.147:56685] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mijn.photo"] [uri "/wp-config.php.bak"] [unique_id "ahH6eWiQ4u-w0UqazYKy-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 05:23:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 01:23:48.595026 2026] [security2:error] [pid 5827:tid 5827] [client 158.173.241.147:36349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schmitzcomm.net"] [uri "/wp-config.php.bak"] [unique_id "ahE55BnO3GWPtQwnLv9vygAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2026-05-22 08:36:08
(1 week ago)
(From [email protected] ) URGENT MESSAGE! 1.3426 BTC IS ALLOCATED WITHDRAW BEFORE EXPIRATION ...
show more
(From [email protected] ) URGENT MESSAGE! 1.3426 BTC IS ALLOCATED WITHDRAW BEFORE EXPIRATION https://telegra.ph/You-Mined-13426-BTC-Message-ID-72805-05-04
VERSION ID: s3iu1l9l7j5l1h4io3xw1l4e6j9r7p1er0wv2w4x4a7y9q8iv5oy4m5y2y0b3u2ih6qx3m2m2i2z1k2td8da7h3h9t9p1a5ux2mx9g4q4b2k6i5y
show less
Phishing
Web Spam