🇬🇧
openstrike.co.uk
2025-12-26 06:14:05
(8 months ago)
8 attacks on PHP URLs:
GET /.well-known/acme-challenge/mah.php HTTP/1.1
Web App Attack
Anonymous
2025-12-25 13:55:01
(8 months ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2025-12-25 12:49:53
(8 months ago)
(mod_security) mod_security (id:240000) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 07:47:58.336624 2025] [security2:error] [pid 16272:tid 16272] [client 191.96.146.167:33621] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||lo-family.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "lo-family.org"] [uri "/images/stories/themes.php"] [unique_id "aU0yflkdaTAQO22YzoRKZQAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-25 09:56:26
(8 months ago)
(mod_security) mod_security (id:240000) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 04:56:18.913832 2025] [security2:error] [pid 2479:tid 2479] [client 191.96.146.167:27333] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||ziccardiart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "ziccardiart.com"] [uri "/images/stories/themes.php"] [unique_id "aU0KQmdB1gYFmz4OTNxpQAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-22 05:51:24
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 22 00:51:17.204478 2025] [security2:error] [pid 19504:tid 19504] [client 191.96.146.167:25415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uppermotradingco.com"] [uri "/backup/sftp-config.json"] [unique_id "aUjcVYEJDKaq07SOfoyE4QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-18 22:44:00
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 18 17:43:52.847206 2025] [security2:error] [pid 7134:tid 7134] [client 191.96.146.167:54255] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoinsquaretrader.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoinsquaretrader.com"] [uri "/mysql.sql"] [unique_id "aUSDqL2OoB5Pr2uAaKrx4AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-18 00:42:37
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 17 19:42:30.907357 2025] [security2:error] [pid 20601:tid 20601] [client 191.96.146.167:56321] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "secureonebank.net"] [uri "/sftp-config.json"] [unique_id "aUNN9gEYVDgZKx5-DrPJJQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-08 14:36:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 09:36:28.601571 2025] [security2:error] [pid 15256:tid 15256] [client 191.96.146.167:30627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asiabeef.network"] [uri "/bak/sftp-config.json"] [unique_id "aTbibDEkBwZsZb1py-XG5QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-30 16:10:17
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 30 11:10:13.511073 2025] [security2:error] [pid 18874:tid 18874] [client 191.96.146.167:34541] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||aico-sal.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aico-sal.com"] [uri "/backup/www.sql"] [unique_id "aSxsZSvXQGY98H42sHvKLQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Penny Packer
2025-11-30 02:40:35
(9 months ago)
Fail2Ban apache-tripwires
Web App Attack
🇩🇪
Vegascosmetics
2025-11-28 22:51:17
(9 months ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2025-11-28 18:33:23
(9 months ago)
3.199 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2025-11-26 17:25:59
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 12:25:52.683853 2025] [security2:error] [pid 16108:tid 16108] [client 191.96.146.167:47853] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kwtlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kwtlaw.com"] [uri "/old/mysql.sql"] [unique_id "aSc4IH2PireojpOLPiGwygAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:01:40
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.96.146.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:01:36.389105 2025] [security2:error] [pid 9377:tid 9377] [client 191.96.146.167:35085] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.crypto-stamps.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.crypto-stamps.com"] [uri "/restore/www.sql"] [unique_id "aSP0wEDtv0gWADQaSyO0ugAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Penny Packer
2025-11-21 00:06:05
(9 months ago)
Fail2Ban apache-tripwires
Web App Attack