๐บ๐ธ
TPI-Abuse
2026-09-30 02:32:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:32:27.157392 2026] [security2:error] [pid 4730:tid 4730] [client 162.158.155.25:13974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geauxcowboys.com"] [uri "/wp-config.php.bak"] [unique_id "arx0u8HBWonq993cAflmjgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:28:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:28:03.110402 2026] [security2:error] [pid 4317:tid 4317] [client 162.158.155.25:11833] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||janyoors.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "janyoors.com"] [uri "/index.php.bak"] [unique_id "arxlo0tJFV_YcFzuZqtagQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:19:24
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:19:17.507849 2026] [security2:error] [pid 16931:tid 16984] [client 162.158.155.25:13100] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leadingedgesupply.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leadingedgesupply.com"] [uri "/index.php.bak"] [unique_id "arwrVf6yfeW53BLD92iIsAAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 06:26:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 02:26:34.409900 2026] [security2:error] [pid 8893:tid 8893] [client 162.158.155.25:11774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rldcompany.com"] [uri "/wp-config.php"] [unique_id "artaGjjzRTiLKVOCw23rkgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 01:15:49
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 21:15:44.708008 2026] [security2:error] [pid 23837:tid 23837] [client 162.158.155.25:9310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ceta-arts.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ceta-arts.com"] [uri "/index.php.bak"] [unique_id "arsRQFuBmZWw9WT5qMHa2gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 11:59:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 07:59:34.465560 2026] [security2:error] [pid 31614:tid 31614] [client 162.158.155.25:9991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-italy.com"] [uri "/.htaccess"] [unique_id "arpWpmSh3W3nZK3J3TYGvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-09 23:22:38
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 20:10:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:10:02.637133 2026] [security2:error] [pid 8061:tid 8061] [client 162.158.155.25:13696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "correo.rallyasturias.com"] [uri "/.git/HEAD"] [unique_id "ao9IGqanwxoxsP4kJS8wuQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-22 08:15:09
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:28:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:28:08.241419 2026] [security2:error] [pid 10507:tid 10507] [client 162.158.155.25:11087] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.exploratorymusic.net"] [uri "/.git/config"] [unique_id "aoUw2IssGrse6N9wBLIFdAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-06 08:18:12
(1 month ago)
Web App Attack
Anonymous
2026-06-16 12:20:03
(3 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฆ๐ฑ
router.al
2026-05-29 04:01:01
(4 months ago)
05/29/2026-04:01:01.025730 162.158.155.25 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple ...
show more
05/29/2026-04:01:01.025730 162.158.155.25 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML
show less
Hacking
๐ฆ๐ฑ
router.al
2026-05-26 13:13:48
(4 months ago)
05/26/2026-13:13:48.592547 162.158.155.25 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple ...
show more
05/26/2026-13:13:48.592547 162.158.155.25 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML
show less
Hacking
๐บ๐ธ
drewf.ink
2026-05-12 18:14:35
(4 months ago)
[18:14] Port scanning. Port(s) scanned: TCP/2087
Port Scan