|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:949110) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 08:31:10.772220 2026] [security2:error] [pid 23291:tid 23291] [client 185.94.33.153:35119] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "jrwoodsrentals.com"] [uri "/.wp-config.php.swp"] [unique_id "ahBMjn-78VIxJPZgvSwyPgAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 03:08:23.127402 2026] [security2:error] [pid 18785:tid 18785] [client 185.94.33.153:32701] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desertautoworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desertautoworks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahAA55qsCpXeok_UeHW0yQAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 14:37:17.405352 2026] [security2:error] [pid 14964:tid 14964] [client 185.94.33.153:10859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bergenoaks.com.velvetculture.com"] [uri "/wp-config.txt"] [unique_id "ag3_XUEmju1Tlc7WwuZgfwAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:15:04.200821 2026] [security2:error] [pid 25682:tid 25698] [client 185.94.33.153:28079] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cynosurelandscapers.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cynosurelandscapers.com"] [uri "/wp-config.inc"] [unique_id "ag3eCDief1UD2nw0WOPCsgAAAIs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:12:15.691791 2026] [security2:error] [pid 30526:tid 30526] [client 185.94.33.153:29819] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||harwoodmechanical.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "harwoodmechanical.com"] [uri "/wp-config.inc"] [unique_id "ag2lH7Mxb0g5ArPOtwXUCwAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.94.33.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 23:12:16.189363 2026] [security2:error] [pid 4556:tid 4556] [client 185.94.33.153:45777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructiondomex.com"] [uri "/wp-config.php.dist"] [unique_id "ag0mkHKbF_VN2Pp-QUJIfgAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
kbeezie
|
|
2026/05/17 04:09:26 [error] 3567417#3567417: *9220 access forbidden by rule, client: 185.94.33.153, ...
show more
2026/05/17 04:09:26 [error] 3567417#3567417: *9220 access forbidden by rule, client: 185.94.33.153, server: karlblessing.com, request: "GET /license.txt HTTP/1.1", host: "karlblessing.com"
2026/05/17 04:09:26 [error] 3567417#3567417: *9211 access forbidden by rule, client: 185.94.33.153, server: karlblessing.com, request: "GET /.env HTTP/1.1", host: "karlblessing.com"
2026/05/17 04:09:26 [error] 3567417#3567417: *9211 access forbidden by rule, client: 185.94.33.153, server: karlblessing.com, request: "GET /readme.html HTTP/1.1", host: "karlblessing.com"
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
masterguru
|
|
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-201)
show less
|
Hacking
|
|
|
๐ต๐ฑ
sefinek.net
|
|
Triggered Cloudflare WAF (firewallCustom) from FI.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
|
Bad Web Bot
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
Anonymous
|
|
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
|
Web App Attack
|
|
|
Anonymous
|
|
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
|
Web App Attack
|
|
|
๐จ๐ฆ
wil.com
|
|
GlobalProtect login attempts with user jphilpott.
|
VPN IP
Brute-Force
|
|
|
๐ฉ๐ช
conseilgouz
|
|
coe-12 : Block return, carriage return, ... characters=>/en/component/weblinks/weblink/52-astroid-de ...
show more
coe-12 : Block return, carriage return, ... characters=>/en/component/weblinks/weblink/52-astroid-de-joomdev-2?catid=14&Itemid=305%27&task=weblink.g...(')
show less
|
Hacking
|
|
|
๐บ๐ธ
fortypoundhead
|
|
PHP vulnerability scan
|
Web App Attack
|
|