๐บ๐ธ
TPI-Abuse
2026-06-03 20:58:54
(5 hours ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 16:58:51.093918 2026] [security2:error] [pid 16110:tid 16110] [client 158.173.241.156:29287] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||accsbg.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "accsbg.org"] [uri "/license.txt"] [unique_id "aiCVi9f2GptSG53SK4Vc7QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 17:41:25
(8 hours ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 13:41:18.820967 2026] [security2:error] [pid 14181:tid 14181] [client 158.173.241.156:32479] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||bayareahiphopforever.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "bayareahiphopforever.org"] [uri "/license.txt"] [unique_id "aiBnPt5RhrKJ7eP0iQeZmgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 13:13:11
(13 hours ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 09:13:06.573231 2026] [security2:error] [pid 31814:tid 31814] [client 158.173.241.156:53755] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||britishfolk.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "britishfolk.org"] [uri "/license.txt"] [unique_id "aiAoYtH1lBo7er1Y8P1UaQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 09:00:09
(17 hours ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 05:00:02.113063 2026] [security2:error] [pid 6438:tid 6470] [client 158.173.241.156:25245] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||cityofmiddleton.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "cityofmiddleton.org"] [uri "/license.txt"] [unique_id "ah_tEpSn4lVNZX74HMjxzwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 10:35:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:34:52.976857 2026] [security2:error] [pid 3526:tid 3526] [client 158.173.241.156:60671] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arellasoc.com"] [uri "/wp-config.php.bak"] [unique_id "ah6xzM5v_kgtIxRCo15qMQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-01 21:05:51
(2 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 15:16:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 11:16:25.256983 2026] [security2:error] [pid 863:tid 863] [client 158.173.241.156:48241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advantagept.org"] [uri "/wp-config.php.bak"] [unique_id "ahRnyXoWg7ZEab9MpwMijQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-24 14:19:24
(1 week ago)
Web attack blocked by Wordfence on kernoverlegsibbe-ijzeren.nl (1 hit). Reported by CRMON.
Web App Attack
๐ง๐ช
cmbplf
2026-05-24 12:44:05
(1 week ago)
317 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-22 09:17:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 05:17:15.207676 2026] [security2:error] [pid 23547:tid 23605] [client 158.173.241.156:59221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "condo.management"] [uri "/wp-config.php.bak"] [unique_id "ahAfG1OyObMtgnBAVoXNtgAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 08:04:26
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 04:04:21.231634 2026] [security2:error] [pid 31137:tid 31137] [client 158.173.241.156:46729] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||clowaterart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clowaterart.com"] [uri "/mailto:[email protected] "] [unique_id "ahAOBbRJ8I3HdHJEnJIBEQAAAB0"], referer: http://clowaterart.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 07:04:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 03:04:33.330530 2026] [security2:error] [pid 28964:tid 28964] [client 158.173.241.156:60207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.link"] [uri "/wp-config.php.bak"] [unique_id "ahAAASnoojyb6bE02R5GjAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2026-05-21 23:05:13
(1 week ago)
(From [email protected] ) URGENT! Act swiftly to get your 1.3426 BTC earnings https://telegra.ph/ ...
show more
(From [email protected] ) URGENT! Act swiftly to get your 1.3426 BTC earnings https://telegra.ph/You-Mined-13426-BTC-Message-ID-846274-05-04
UUID: u8ro0z1l3h9d8j2xy9xs0j3c3c4s3f5qm4cf3k8c8s3x6f1lv8jj5j0x4e7m8k2eb5xl7d3w6g4g1r8ls5tk4x1d8c5y9c8ak3jw4h4y9v6l4b0j
show less
Phishing
Web Spam
๐ซ๐ท
viki53
2026-05-21 22:31:30
(1 week ago)
Contact form spam
Web Spam
๐บ๐ธ
nowyouknow
2026-05-21 21:08:15
(1 week ago)
(From [email protected] ) IMPORTANT MESSAGE! Donโt miss this 1.3426 BTC opportunity withdraw n ...
show more
(From [email protected] ) IMPORTANT MESSAGE! Donโt miss this 1.3426 BTC opportunity withdraw now https://telegra.ph/You-Mined-13426-BTC-Message-ID-411201-05-04
USER ID: t2lb4a3i6q7o8w5si3gi0x5h6l9n0a7bb6ok3x2f6u1j5e2og8vn9k4r7q6r8c4nx0ua8t3s5c0r8t5fy8et9p3y0d9m9u7sj3je7s0r8m7r2l7g
show less
Phishing
Web Spam