๐บ๐ธ
TPI-Abuse
2026-05-21 23:17:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 167.253.19.244 (167-253-19-244.cloudairone.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.19.244 (167-253-19-244.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 19:17:01.761723 2026] [security2:error] [pid 26481:tid 26481] [client 167.253.19.244:34825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.instagenii.ficklepassionproductions.com"] [uri "/wp-config.php.bak"] [unique_id "ag-SbcuwoWHGfB1JeDY3DAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 21:30:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 167.253.19.244 (167-253-19-244.cloudairone.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.19.244 (167-253-19-244.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 17:29:59.929316 2026] [security2:error] [pid 19770:tid 19786] [client 167.253.19.244:29005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neutrahouse1939.ward-bergerhouse.org"] [uri "/wp-config.php.save"] [unique_id "ag4n10xDQ309VKvUAOq3VAAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 12:55:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 167.253.19.244 (167-253-19-244.cloudairone.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.19.244 (167-253-19-244.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:55:48.627062 2026] [security2:error] [pid 17999:tid 17999] [client 167.253.19.244:61055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "automatebi.com"] [uri "/wp-config.php.dist"] [unique_id "ag2vVGxwY64uLAB7w1aNTQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-04-28 04:45:44
(1 month ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-04-17 02:18:41
(1 month ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-16 00:44:04
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 167.253.19.244 (167-253-19-244.cloudairone.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 167.253.19.244 (167-253-19-244.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 20:43:58.111021 2026] [security2:error] [pid 2185018:tid 2185018] [client 167.253.19.244:40813] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/graphics/Thumbs.db"] [unique_id "aeAwzi76dCMECv8gYOiucgAAAAo"], referer: https://vitalitywebb.com/backstore/graphics/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-01 20:55:38
(2 months ago)
"POST /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
๐ง๐ช
voormedia
2026-03-30 16:46:00
(2 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
Anonymous
2026-03-24 21:24:14
(2 months ago)
[Firewall Canary] Temporary ban due to firewall rule match [URI canary:*/xmlrpc.php]
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-03-22 22:25:27
(2 months ago)
XML RPC Scan Activities: "2026-03-23T05:25:27.581+07:00" "/xmlrpc.php" "167.253.19.244" "AppleWebKit ...
show more
XML RPC Scan Activities: "2026-03-23T05:25:27.581+07:00" "/xmlrpc.php" "167.253.19.244" "AppleWebKit/537.37 (KHTML, like Gecko111)"
show less
Web App Attack
Brute-Force
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-03-16 19:33:18
(2 months ago)
XML RPC Scan Activities: "2026-03-17T02:33:18.446+07:00" "/xmlrpc.php" "167.253.19.244" "Mozilla/5.0 ...
show more
XML RPC Scan Activities: "2026-03-17T02:33:18.446+07:00" "/xmlrpc.php" "167.253.19.244" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:146.0) Gecko/20100101 Firefox/146.0"
show less
Web App Attack
Brute-Force
๐ง๐ช
voormedia
2026-03-09 12:39:52
(2 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ง๐ช
voormedia
2026-03-04 10:24:04
(3 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐จ๐ญ
backslash
2026-02-10 02:35:25
(3 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
๐ฉ๐ช
HandyTreff.de
2026-01-06 12:29:02
(5 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -29.215 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -29.215 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.1958.1
show less
Bad Web Bot
Web App Attack