πΊπΈ
TPI-Abuse
2026-09-17 13:41:06
(3 days ago)
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:40:59.820888 2026] [security2:error] [pid 25485:tid 25485] [client 168.113.16.113:43351] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||www.timetemple.org|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.timetemple.org"] [uri "/"] [unique_id "aqvt6yPysxuRjzEGWYoZ6wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 16:43:56
(3 days ago)
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:43:48.301250 2026] [security2:error] [pid 20143:tid 20143] [client 168.113.16.113:44141] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||www.thesteeldrumman.com|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.thesteeldrumman.com"] [uri "/"] [unique_id "aqrHRKl5TtqQ5O_DQ3Hi1AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-16 13:47:11
(4 days ago)
Suspicious HTTP(s) activity without a user agent provided
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-15 06:29:52
(5 days ago)
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:29:44.853069 2026] [security2:error] [pid 17568:tid 17568] [client 168.113.16.113:53607] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||thenolangroup.llc|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "thenolangroup.llc"] [uri "/"] [unique_id "aqjl2Psr7xIwuJCnudXbZAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-15 04:32:04
(5 days ago)
Suspicious HTTP(s) activity without a user agent provided
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-13 22:14:47
(6 days ago)
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:14:41.196337 2026] [security2:error] [pid 8724:tid 8771] [client 168.113.16.113:42975] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||teritemme.com|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "teritemme.com"] [uri "/"] [unique_id "aqcgUQpTkTt-fltXPDUuRAAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-13 15:25:14
(6 days ago)
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:25:07.132572 2026] [security2:error] [pid 1759:tid 1759] [client 168.113.16.113:54355] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||www.teleplussolutions.com|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.teleplussolutions.com"] [uri "/"] [unique_id "aqbAU-YbTLeHU2vLPoeQTAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-13 01:53:38
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /wp-json/batch/v1 | ua: - | 2026-09-13 01:53 UTC
show less
Hacking
Web App Attack
π¨π
Origon
2026-09-12 14:40:29
(1 week ago)
http-cve-probing - IP: 168.113.16.113 - time="2026-09-12T16:40:29+02:00" level=info msg="(555f66b4f ...
show more
http-cve-probing - IP: 168.113.16.113 - time="2026-09-12T16:40:29+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-cve-probing by ip 168.113.16.113 (US/0) : 4h ban on Ip 168.113.16.113" module=db
show less
Web App Attack
π©πͺ
LRob
2026-09-12 12:21:20
(1 week ago)
Asking over plain http and never following the redirect served β a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served β a crawler that reads nothing it asks for | method: GET | path: /wp-json/ | 2026-09-12 12:21 UTC
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-12 09:59:55
(1 week ago)
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:59:48.407782 2026] [security2:error] [pid 11403:tid 11403] [client 168.113.16.113:53413] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||terrageosynthetics.com|F|2"] [data "/site/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "terrageosynthetics.com"] [uri "/site/"] [unique_id "aqUilOD3YBH5oui1zkAttgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-12 07:42:48
(1 week ago)
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:42:44.362190 2026] [security2:error] [pid 814:tid 814] [client 168.113.16.113:38393] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||the-it-man.com|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "the-it-man.com"] [uri "/"] [unique_id "aqUCdIsNaBP9h318x3E3nQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-12 05:44:24
(1 week ago)
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217200) triggered by 168.113.16.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:44:20.720507 2026] [security2:error] [pid 18142:tid 18142] [client 168.113.16.113:40579] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||tcjohnston.com|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "tcjohnston.com"] [uri "/"] [unique_id "aqTmtK-CShFccK1b9at5BQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
LRob
2026-09-12 03:10:32
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /wp-json/batch/v1 | ua: - | 2026-09-12 03:10 UTC
show less
Hacking
Web App Attack