๐ซ๐ท
dynamix
2026-10-09 20:25:56
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-10-06 18:28:45
(3 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 16:20:47
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 12:20:40.794721 2026] [security2:error] [pid 5246:tid 5258] [client 162.158.155.203:13173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dulemba.com"] [uri "/wp-config.php.bak"] [unique_id "asJ82H00jw4o8S6QMqVJJAAAAco"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:42:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:42:47.456193 2026] [security2:error] [pid 22237:tid 22237] [client 162.158.155.203:12111] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pjv.us"] [uri "/wp-config.php"] [unique_id "ar5_d4QSRSWlEe7bUOuygAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:25:34
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:25:27.192196 2026] [security2:error] [pid 7735:tid 7735] [client 162.158.155.203:13543] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||windtime.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "windtime.com"] [uri "/index.php.bak"] [unique_id "ar0Nx8xyPdWlP6QznzaExQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:02:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:02:11.806096 2026] [security2:error] [pid 27449:tid 27449] [client 162.158.155.203:13350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenowhere-men.com"] [uri "/wp-config.php"] [unique_id "arxDcxkopblatZSHdszdXgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 03:09:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 23:09:06.112886 2026] [security2:error] [pid 1741:tid 1741] [client 162.158.155.203:9231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jsw4.net"] [uri "/.htaccess"] [unique_id "arsr0txDH7iV8wprQTgzwwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 11:30:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 07:30:12.046909 2026] [security2:error] [pid 14745:tid 14753] [client 162.158.155.203:9799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dulemba.com"] [uri "/.htaccess"] [unique_id "arpPxDr7ORXSOYdKuT_YZQAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 11:36:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:36:09.626132 2026] [security2:error] [pid 31457:tid 31457] [client 162.158.155.203:9630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.oiseauxsisters.com"] [uri "/.git/config"] [unique_id "ao7Pqd3uKZaNrhH-NK_QKAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-21 13:11:56
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 10:07:59
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ซ๐ท
dynamix
2026-07-28 11:43:18
(2 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
wimaxnz
2026-05-14 02:03:56
(4 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
wimaxnz
2026-05-05 00:07:39
(5 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
wimaxnz
2026-05-03 00:53:55
(5 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan