๐บ๐ธ
TPI-Abuse
2026-09-30 15:25:40
(27 minutes ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:25:38.150080 2026] [security2:error] [pid 24753:tid 24753] [client 162.158.154.158:13779] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||paulpasquali.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paulpasquali.com"] [uri "/index.php.bak"] [unique_id "ar0p8gQP-fsBEV2Vb_qHewAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:19:37
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:19:32.667396 2026] [security2:error] [pid 6039:tid 6039] [client 162.158.154.158:14191] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blog.mosherpit.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blog.mosherpit.com"] [uri "/index.php.bak"] [unique_id "ar0adPjgKWc1o2OPI3oRiAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 06:46:13
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:46:09.273187 2026] [security2:error] [pid 9051:tid 9051] [client 162.158.154.158:10080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angeladuffin.com"] [uri "/wp-config.php.bak"] [unique_id "arywMX9CCPphh5ShMwjOrgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:39:36
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:39:30.527122 2026] [security2:error] [pid 24672:tid 24672] [client 162.158.154.158:13597] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kporterdesign.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kporterdesign.com"] [uri "/index.php.bak"] [unique_id "arx2Ylp8j4jem-SqMW6DFAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:08:30
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:08:27.571855 2026] [security2:error] [pid 31352:tid 31352] [client 162.158.154.158:10637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wmbbqing.com"] [uri "/.htaccess"] [unique_id "arwoy66NlItvZ2oMOWZChgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 13:03:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:03:29.140094 2026] [security2:error] [pid 21177:tid 21177] [client 162.158.154.158:13545] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lasertherapyoc.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lasertherapyoc.com"] [uri "/index.php.bak"] [unique_id "aru3IZ6L7ZgzDm_BvtRp0QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 07:34:48
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:34:45.207698 2026] [security2:error] [pid 11377:tid 11377] [client 162.158.154.158:10461] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rangejudging.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rangejudging.com"] [uri "/index.php.bak"] [unique_id "artqFS5scvp9hJRKO_6uIwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 05:32:46
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 01:32:42.606907 2026] [security2:error] [pid 12887:tid 12887] [client 162.158.154.158:11231] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.clcmillvale.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.clcmillvale.com"] [uri "/index.php.bak"] [unique_id "artNeregqFUIuFZ310aVDAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 02:47:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 22:47:27.932902 2026] [security2:error] [pid 4612:tid 4666] [client 162.158.154.158:10483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centurylink-sales.com"] [uri "/wp-config.php"] [unique_id "arsmv4skV6o6EhPMGHj2OQAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-08-31 00:49:59
(4 weeks ago)
2026/08/31 00:49:58 [error] 1099404#1099404: *50932 access forbidden by rule, client: 162.158.154.15 ...
show more
2026/08/31 00:49:58 [error] 1099404#1099404: *50932 access forbidden by rule, client: 162.158.154.158, server: wynnesmiles.com, request: "GET /.git/config HTTP/2.0", host: "wynnesmiles.com"
...
show less
Web App Attack
๐บ๐ธ
LotPhantom
2026-08-28 16:34:49
(1 month ago)
2026/08/28 16:34:48 [error] 876274#876274: *21859 access forbidden by rule, client: 162.158.154.158, ...
show more
2026/08/28 16:34:48 [error] 876274#876274: *21859 access forbidden by rule, client: 162.158.154.158, server: wynnesmiles.com, request: "GET /.git/config HTTP/2.0", host: "wynnesmiles.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 05:54:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:54:05.619470 2026] [security2:error] [pid 22411:tid 22411] [client 162.158.154.158:12893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.infinite-e.com"] [uri "/.git/config"] [unique_id "ao5_fWaQvFJ2QpFV0XrTowAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 01:36:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 21:36:11.752593 2026] [security2:error] [pid 16111:tid 16114] [client 162.158.154.158:13703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.skillscredentials.com"] [uri "/.git/HEAD"] [unique_id "aozxi5AnuEacFs3Ge65ixgAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 07:56:47
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-20 13:58:39
(1 month ago)
Web App Attack