๐ฉ๐ช
big-cloud.nl
2026-10-08 06:53:05
(4 hours ago)
Try to access /xmlrpc.php
Web App Attack
Anonymous
2026-10-08 05:12:03
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-admin/install.php HTTP/1.1, GET /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 02:37:54
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 22:37:50.490828 2026] [security2:error] [pid 27851:tid 27851] [client 161.35.154.90:57536] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gabbyspetnanny.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gabbyspetnanny.com"] [uri "/wp-content/debug.log"] [unique_id "ascB_j1eiCbyTXZgoFfWZgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-10-07 19:37:13
(16 hours ago)
(XMLRPC) WP XMLRPC Attack 161.35.154.90 (NL/The Netherlands/North Holland/Amsterdam/-/[AS14061 Digit ...
show more
(XMLRPC) WP XMLRPC Attack 161.35.154.90 (NL/The Netherlands/North Holland/Amsterdam/-/[AS14061 DigitalOcean, LLC]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 161.35.154.90 - - [07/Oct/2026:22:31:43 +0300] "GET /xmlrpc.php HTTP/1.1" 503 18933 "-" "TLDWPBot/1.0 (+https://tldwp.com/about.php)"
show less
Port Scan
๐ณ๐ฑ
Alt255
2026-10-07 17:49:04
(17 hours ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 161.35.154.90 - - [07/Oct/2026:19:49:03 +0200] "GET /phpinfo.php HTTP/1.1" 301 6335 "-" "TLDWPBot/1.0 (+https://tldwp.com/about.php)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 09:24:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:23:59.699325 2026] [security2:error] [pid 24284:tid 24284] [client 161.35.154.90:39306] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||serviciodepinturadecasas.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "serviciodepinturadecasas.com"] [uri "/wp-content/debug.log"] [unique_id "asYPr3WHGZEQfs14RR9guAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 08:59:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:59:47.558815 2026] [security2:error] [pid 16742:tid 16742] [client 161.35.154.90:41052] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||peterjohnsonauthor.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "peterjohnsonauthor.com"] [uri "/wp-content/debug.log"] [unique_id "asYKA7WONYRyKAwVosuGSgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-10-07 05:25:02
(1 day ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
paissangroup
2026-10-07 05:21:46
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:40:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:40:02.256883 2026] [security2:error] [pid 6513:tid 6548] [client 161.35.154.90:51142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||georgementz.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "georgementz.com"] [uri "/wp-content/debug.log"] [unique_id "asWxAtK6iXF2D0izez67VwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:28:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:28:38.412640 2026] [security2:error] [pid 25514:tid 25514] [client 161.35.154.90:37472] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||paulshorrock.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paulshorrock.com"] [uri "/wp-content/debug.log"] [unique_id "asVoBgZmJXvao5EVbS3QwQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-06 19:47:16
(1 day ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 17:11:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 13:11:12.501651 2026] [security2:error] [pid 32536:tid 32563] [client 161.35.154.90:41240] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ccgparquitectos.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ccgparquitectos.com"] [uri "/wp-content/debug.log"] [unique_id "asUrsNmRsAte0o8m5xw-UAAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:52:57
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 161.35.154.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:52:52.408611 2026] [security2:error] [pid 32443:tid 32443] [client 161.35.154.90:60366] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pattenden.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pattenden.com"] [uri "/wp-content/debug.log"] [unique_id "asTvJIb0YtbsBPpDOsf72gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-06 12:40:19
(1 day ago)
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 16 ...
show more
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 161.35.154.90 - - \[06/Oct/2026:14:40:14 +0200\] "GET /phpinfo.php HTTP/1.1" 200 183651 "-" "TLDWPBot/1.0 \(+https://tldwp.com/about.php\)"
...
show less
Bad Web Bot
Web App Attack