๐บ๐ธ
TPI-Abuse
2026-09-29 14:51:04
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:50:58.916518 2026] [security2:error] [pid 9746:tid 9746] [client 162.158.63.135:13635] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thompsonboatworks.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thompsonboatworks.com"] [uri "/index.php.bak"] [unique_id "arvQUqxc3FdLqR5TGJLQtAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 10:59:59
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:59:54.847304 2026] [security2:error] [pid 25784:tid 25784] [client 162.158.63.135:14231] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.concentricsteel.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.concentricsteel.com"] [uri "/index.php.bak"] [unique_id "aruaKg6WMOdqyNLJ-6QgzwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 22:14:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 18:14:43.028302 2026] [security2:error] [pid 27526:tid 27526] [client 162.158.63.135:13812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "parasolia.angelabcomics.com"] [uri "/.htaccess"] [unique_id "arrm07h5W5FQFQYGFkdJDwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 19:34:32
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 15:34:28.716818 2026] [security2:error] [pid 8798:tid 8798] [client 162.158.63.135:10074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pinecasso.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pinecasso.com"] [uri "/index.php.bak"] [unique_id "arrBRDiMZWPWHQCCWokTzAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 14:13:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 10:13:09.033097 2026] [security2:error] [pid 9423:tid 9423] [client 162.158.63.135:12828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mtl.microkerneltechnologies.com"] [uri "/.htaccess"] [unique_id "arfS9cXHGapIs3zN0qatBQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 12:26:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 08:26:34.008724 2026] [security2:error] [pid 31935:tid 31952] [client 162.158.63.135:14106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "woofnrose.com"] [uri "/.htaccess"] [unique_id "are5-sH5LnVKu-v5Fs4hlQAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 13:29:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:29:02.388840 2026] [security2:error] [pid 27784:tid 27784] [client 162.158.63.135:12848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "enriquejezik.com"] [uri "/.env"] [unique_id "apl2Hj0iaH4ejsp-h2VMgQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 05:44:29
(1 month ago)
Aggressive web scan
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 07:17:44
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-05 02:45:38
(2 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 17:42:05
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 13:41:59.174799 2026] [security2:error] [pid 16556:tid 16556] [client 162.158.63.135:11658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.wlsn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.wlsn.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "alfGZ5hS6Xv42GrwCpZlZgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
CrystalMaker
2026-07-02 01:31:45
(3 months ago)
Vulnerability scan - GET /api/debug HTTP/2.0
Hacking
๐บ๐ธ
lostswordfish.com
2026-04-16 06:00:05
(5 months ago)
Wordfence waf block on kcuar
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:11:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:11:51.431048 2026] [security2:error] [pid 8506:tid 8506] [client 162.158.63.135:9585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tribecalledfamilypodcast.org"] [uri "/.env.local"] [unique_id "ab3wV1tAij9uKOuFSdvR_AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:47:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:47:50.691989 2026] [security2:error] [pid 23590:tid 23590] [client 162.158.63.135:14132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.informant-systems.com"] [uri "/.env.example"] [unique_id "ab0Jtjc4crddbQo2WYm2HQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack