🇪🇸
librebit
2026-09-02 14:01:36
(10 hours ago)
Brute force
Brute-Force
🇺🇸
TPI-Abuse
2026-06-15 10:34:18
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 06:34:11.698443 2026] [security2:error] [pid 24913:tid 24913] [client 178.20.28.210:63735] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "schlegelcreative.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_VIwRBaPX-QcqhpfP-ygAAABY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-30 14:13:37
(3 months ago)
FPROCO WEBEXPLOIT 178.20.28.210 (178.20.28.210)
Web App Attack
🇺🇸
TPI-Abuse
2026-05-27 06:50:42
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 02:50:38.734428 2026] [security2:error] [pid 1415:tid 1415] [client 178.20.28.210:51291] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||opere.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "opere.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahaUPuH5-F96b4L3IC2bfQAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-05-21 14:17:14
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-05-07 13:41:11
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 09:41:03.233948 2026] [security2:error] [pid 13999:tid 13999] [client 178.20.28.210:31017] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sahinozalit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sahinozalit.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afyWb3B-B0fQrxTlgKBU5QAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-29 19:20:17
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 15:20:10.529741 2026] [security2:error] [pid 25259:tid 25259] [client 178.20.28.210:30293] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thepercussionworks.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thepercussionworks.com"] [uri "/s3cmd.ini"] [unique_id "afJZ6k_w1eN57smzm1w_FQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-28 14:16:37
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 10:16:32.582665 2026] [security2:error] [pid 11707:tid 11707] [client 178.20.28.210:50205] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.informativearticles.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.informativearticles.com"] [uri "/s3cmd.ini"] [unique_id "afDBQMp3raJ7ajWW2BVwKAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
noise.agency
2026-04-27 23:20:08
(4 months ago)
(mod_security) mod_security triggered on hostname [redacted] 178.20.28.210 (US/United States/-)
SQL Injection
🇺🇸
TPI-Abuse
2026-04-27 20:59:55
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 16:59:50.759512 2026] [security2:error] [pid 26138:tid 26138] [client 178.20.28.210:37179] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.infinite-a.com.sendalawyerletter.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.infinite-a.com.sendalawyerletter.com"] [uri "/s3cmd.ini"] [unique_id "ae_ORtJj7pQrSpkHuRUOoQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-04-27 04:44:25
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-04-27 04:43:48
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 00:43:41.192001 2026] [security2:error] [pid 28484:tid 28484] [client 178.20.28.210:53125] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vansfanz.rollinchassis.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vansfanz.rollinchassis.com"] [uri "/s3cmd.ini"] [unique_id "ae7pfcHX-fI61x0HAZ5ArwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-26 12:35:15
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 178.20.28.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 08:35:07.684859 2026] [security2:error] [pid 9992:tid 9992] [client 178.20.28.210:20687] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.coolcustomproducts.benshermanguitar.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.coolcustomproducts.benshermanguitar.com"] [uri "/s3cmd.ini"] [unique_id "ae4Gez3dwQ7G4zwW_8iMSQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
oncord
2025-12-19 19:02:51
(8 months ago)
Form spam
Web Spam
🇩🇪
Packets-Decreaser.NET
2025-12-10 14:34:55
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam