๐ฎ๐น
sssrit
2026-08-20 10:44:08
(1 month ago)
185.156.72.21 - - [20/Aug/2026:12:44:07 +0200] "GET /wp-content/uploads/sites/3/2020/07/Forum-Vedeme ...
show more
185.156.72.21 - - [20/Aug/2026:12:44:07 +0200] "GET /wp-content/uploads/sites/3/2020/07/Forum-Vedemecum-x-adeguamenti-Statuti.pdf HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ท๐บ
DZBOT
2026-06-30 15:41:13
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฏ๐ต
HeliJP
2026-03-17 05:45:09
(6 months ago)
2026-03-17T05:13:54Z - Recognized attacks\bad behavior from IP address 185.156.72.21 on port 443\80 ...
show more
2026-03-17T05:13:54Z - Recognized attacks\bad behavior from IP address 185.156.72.21 on port 443\80 (3 daily hits): client denied by server configuration
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Web App Attack
Anonymous
2026-02-19 18:24:52
(7 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-14 10:49:28
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 05:49:19.282415 2026] [security2:error] [pid 24878:tid 24878] [client 185.156.72.21:50109] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "aWd0rzU8dYpLhffNGkbhpAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-01-14 03:03:52
(8 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-01-11 20:05:32
(8 months ago)
Web server attack
Hacking
Web App Attack
๐ฆ๐บ
MAGIC
2025-12-26 02:14:25
(8 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-12-08 14:40:11
(9 months ago)
wordpress-trap
Web App Attack
๐จ๐ญ
rt
2025-11-14 08:06:18
(10 months ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 16:41:20
(10 months ago)
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 11:41:12.271493 2025] [security2:error] [pid 16297:tid 16297] [client 185.156.72.21:44791] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||scoutinsignia.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "scoutinsignia.com"] [uri "/insignia/rfront.jpg"] [unique_id "aQ9yqLCEEBIYXmLRk17hJgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 09:29:36
(10 months ago)
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 04:29:29.875214 2025] [security2:error] [pid 9878:tid 9937] [client 185.156.72.21:40347] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||pref-realestate.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "pref-realestate.com"] [uri "/wp-content/uploads/2022/05/Pool2-1024x640.jpg"] [unique_id "aQ8Neagu_sxYVkWzsTgPggAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 04:52:30
(10 months ago)
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 07 23:52:20.474316 2025] [security2:error] [pid 18951:tid 18951] [client 185.156.72.21:38841] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.dismain.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dismain.com"] [uri "/tienda/images/articulos/_5q80l5oc0_g.jpg"] [unique_id "aQ7MhJ5BP1BcJy39n2i4JwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 04:04:13
(10 months ago)
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 07 23:04:05.513085 2025] [security2:error] [pid 14605:tid 14605] [client 185.156.72.21:49355] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.verdeprofundo.net|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.verdeprofundo.net"] [uri "/wp-content/uploads/2013/03/Adrian-Hordyk.jpg"] [unique_id "aQ7BNapFse4kKHJhsQwVxgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 00:17:12
(10 months ago)
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 185.156.72.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 07 19:17:02.916723 2025] [security2:error] [pid 28957:tid 28957] [client 185.156.72.21:39331] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.loneoakhoney.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.loneoakhoney.com"] [uri "/wp-content/uploads/2017/07/MARESTAIL3-225x300.jpg"] [unique_id "aQ6L_jhmKQF8Xwb-XXi7DgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack