๐บ๐ธ
TPI-Abuse
2026-07-28 15:21:31
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 11:21:26.232026 2026] [security2:error] [pid 2112385:tid 2112385] [client 166.1.131.58:22689] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barabesi.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barabesi.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amjI9i-6ebpvg2-yHlrLjwAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-07-28 14:07:50
(8 hours ago)
Web attack/Malicious activity detected
Web App Attack
๐จ๐ฆ
DRI
2026-07-20 00:37:26
(1 week ago)
Web attack/Malicious activity detected
Web App Attack
๐ฉ๐ช
stinpriza
2026-07-18 20:14:26
(1 week ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 02:41:27
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 22:41:19.963774 2026] [security2:error] [pid 5900:tid 5900] [client 166.1.131.58:37849] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||purebinary.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "purebinary.com"] [uri "/wp-json/wp/v2/users"] [unique_id "almWT0YxaKtEyQSJxuYaPwAAABo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 16:47:00
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 12:46:55.432670 2026] [security2:error] [pid 7272:tid 7272] [client 166.1.131.58:34255] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puoci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puoci.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alkK_zHbQp9DSBNj83UrGAAAABQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2025-05-09 13:29:40
(1 year ago)
vee-13 : Block SQL injections=>/component/weblinks/?task=weblink.go&catid=15%3aannonces&id=4 ...
show more
vee-13 : Block SQL injections=>/component/weblinks/?task=weblink.go&catid=15%3aannonces&id=45%3aclassic-number%24%24+AND+%2...( AND)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-05-09 13:24:36
(1 year ago)
(mod_security) mod_security (id:210410) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210410) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 09 09:24:28.336808 2025] [security2:error] [pid 1195606:tid 1195606] [client 166.1.131.58:28081] [client 166.1.131.58] ModSecurity: Access denied with code 403 (phase 2). Found 1 byte(s) in ARGS:view outside range: 1-255. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "95"] [id "210410"] [rev "4"] [msg "COMODO WAF: Invalid character in request||www.southtncardio.com|F|3"] [data "ARGS:view=page1/**/UNIOUNIONN/**/SELESELECTCT/**/UsEr,PaSsWoRd/**/FROFROMM/**/UsErS/**/WHEWHERERE/**/iD LIKE 1\\x00"] [severity "ERROR"] [tag "CWAF"] [tag "Protocol"] [hostname "www.southtncardio.com"] [uri "/index.php"] [unique_id "aB4CDJafJnQKfZkik8hABQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2025-05-05 13:30:53
(1 year ago)
WAF: SQLi vulnerability in aWeb Cart Watching System for Virtuemart v1.0.7 for Joomla! (CVE-2016-101 ...
show more
WAF: SQLi vulnerability in aWeb Cart Watching System for Virtuemart v1.0.7 for Joomla! (CVE-2016-10114) 2- srv1acc
show less
Email Spam
Brute-Force
Anonymous
2025-03-30 10:13:41
(1 year ago)
This IP was involved in an brute force and password spray attack on 2025/03/30 05:10:02
Port Scan
Brute-Force
Exploited Host
Web App Attack
Anonymous
2025-03-28 10:06:39
(1 year ago)
This IP was involved in an brute force and password spray attack on 2025/03/28 05:01:25
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐ธ๐ช
OnTheEdge
2025-03-06 08:48:30
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-11 12:46:55
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 11 07:46:49.357395 2025] [security2:error] [pid 17528:tid 17528] [client 166.1.131.58:33331] [client 166.1.131.58] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anythingsoldworldwide.com"] [uri "/.env"] [unique_id "Z6tGufvn3LsftVhgCHVUwAAAAAE"], referer: https://a00057.tiiny.site/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-17 21:12:36
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210740) triggered by 166.1.131.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 17:12:29.698233 2024] [security2:error] [pid 31855:tid 31855] [client 166.1.131.58:62123] [client 166.1.131.58] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||draindoctor.us|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "draindoctor.us"] [uri "/"] [unique_id "ZsESPV3aCK2XnSClyWvNwwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
syokadmin
2024-01-17 09:34:11
(2 years ago)
(cpanel) Failed cPanel login from 166.1.131.58 (FI/Finland/-): 1 in the last 3600 secs
Brute-Force
Web App Attack