π¬π§
Oakley
2026-07-10 06:53:18
(1 month ago)
(mod_security) mod_security (id:900178) triggered by 167.253.19.114 (US/United States/167-253-19-114 ...
show more
(mod_security) mod_security (id:900178) triggered by 167.253.19.114 (US/United States/167-253-19-114.cloudairone.com): 5 in the last 900 secs
show less
Web App Attack
Hacking
π¬π§
Oakley
2026-06-09 05:49:10
(2 months ago)
(mod_security) mod_security (id:900177) triggered by 167.253.19.114 (US/United States/167-253-19-114 ...
show more
(mod_security) mod_security (id:900177) triggered by 167.253.19.114 (US/United States/167-253-19-114.cloudairone.com): 5 in the last 900 secs
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-05-22 11:48:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 167.253.19.114 (167-253-19-114.cloudairone.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.19.114 (167-253-19-114.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:48:05.312671 2026] [security2:error] [pid 16582:tid 16582] [client 167.253.19.114:10089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cosplayculture.com"] [uri "/wp-config.php.orig"] [unique_id "ahBCdfm_Q3H2v1BRbs2IdAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-20 18:31:05
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 167.253.19.114 (167-253-19-114.cloudairone.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 167.253.19.114 (167-253-19-114.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 14:30:59.341390 2026] [security2:error] [pid 26237:tid 26237] [client 167.253.19.114:39217] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kawkacevents.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kawkacevents.com"] [uri "/wp-config.inc"] [unique_id "ag39419znl32fKwvUKolxAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-20 12:42:38
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 167.253.19.114 (167-253-19-114.cloudairone.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.19.114 (167-253-19-114.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:42:30.431060 2026] [security2:error] [pid 18855:tid 18855] [client 167.253.19.114:47779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.store.newmooncafe.com"] [uri "/wp-config.php.old"] [unique_id "ag2sNo-PElH54svIBEPjhwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-05-19 02:05:46
(3 months ago)
Scanning/Probing (34)
Brute-Force
Web App Attack
πͺπΈ
masterguru
2026-04-15 18:16:43
(4 months ago)
Restricted File Access Attempt. Matched phrase "wp-config.php" at REQUEST_FILENAME. (930130-122)
Hacking
Web App Attack
πΊπΈ
Psycho Solutions LLC
2026-02-27 02:55:00
(5 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User A ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User Agent: N/A - Timestamp: 2/27/2026 2:55 am (UTC-6)
show less
Web App Attack
Bad Web Bot
Web Spam
Hacking
π§πͺ
voormedia
2026-02-24 23:03:22
(5 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
π¨π
backslash
2025-11-19 21:40:30
(9 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-09-12 20:06:44
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 167.253.19.114 (167-253-19-114.cloudairone.com) ...
show more
(mod_security) mod_security (id:210350) triggered by 167.253.19.114 (167-253-19-114.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 12 16:06:40.720211 2025] [security2:error] [pid 22981:tid 22981] [client 167.253.19.114:36601] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||wnysnowsports.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wnysnowsports.com"] [uri "/"] [unique_id "aMR9UOGtEQSq9FvZkIO_UQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack