π©πͺ
paissangroup
2026-01-05 16:01:46
(9 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-05 08:23:11
(9 months ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 05 03:23:03.450726 2026] [security2:error] [pid 11844:tid 11844] [client 173.239.196.167:62559] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||infolinkqr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "infolinkqr.com"] [uri "/images/stories/themes.php"] [unique_id "aVt059L3VPJNSUoBW6twqwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-04 21:50:33
(9 months ago)
173.239.196.167 - - [04/Jan/2026:22:50:27 +0100] "GET /modules/mod_simplefileuploadv1.3/elements/udd ...
show more
173.239.196.167 - - [04/Jan/2026:22:50:27 +0100] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
...
show less
Web App Attack
π³πΏ
Antinson
2026-01-04 21:26:15
(9 months ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
π¨π¦
polycoda
2026-01-04 19:13:11
(9 months ago)
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π Admin Panel Scanning (Decay-Based) - β Exce ...
show more
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π Admin Panel Scanning (Decay-Based) - β Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-01-04 16:52:11
(9 months ago)
Multiple WAF Violations
Web App Attack
πΈπ¬
Cloudkul Cloudkul
2026-01-04 16:06:30
(9 months ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-04 15:46:25
(9 months ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 10:46:20.813918 2026] [security2:error] [pid 6066:tid 6066] [client 173.239.196.167:33435] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||corinthianscruise.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "corinthianscruise.org"] [uri "/images/stories/themes.php"] [unique_id "aVqLTLUd7a0ykDB7P0J3_QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-04 12:48:28
(9 months ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 07:48:22.006528 2026] [security2:error] [pid 11501:tid 11522] [client 173.239.196.167:56649] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||192.64.150.23|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "192.64.150.23"] [uri "/images/stories/themes.php"] [unique_id "aVphlmq5tLNqJd8ZTyRX3AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-04 12:13:22
(9 months ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 07:13:17.114530 2026] [security2:error] [pid 22295:tid 22295] [client 173.239.196.167:45893] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||normajeanebook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "normajeanebook.com"] [uri "/images/stories/themes.php"] [unique_id "aVpZXS4px76cRXYSXvQUiAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2025-12-29 04:35:51
(9 months ago)
Multiple WAF Violations
Web App Attack
π³πΏ
Antinson
2025-12-28 18:28:34
(9 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
π·πΊ
sms.ru
2025-12-28 15:13:54
(9 months ago)
/wp-admin/css/colors/blue/rk2.php
Web App Attack
π©πͺ
paissangroup
2025-12-28 02:03:26
(9 months ago)
Multiple WAF Violations
Web App Attack
π³πΏ
Antinson
2025-12-27 20:11:19
(9 months ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot