|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 193.56.20.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.20.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 13:20:11.247083 2026] [security2:error] [pid 6016:tid 6016] [client 193.56.20.211:51453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bigheartskitchen.lahamradio.com"] [uri "/wp-config.php.orig"] [unique_id "ag8-y4UNfh1g5U8LsBOaZwAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 193.56.20.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 193.56.20.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 16:42:23.641680 2026] [security2:error] [pid 21766:tid 21766] [client 193.56.20.211:56719] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||geckoturner.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "geckoturner.com"] [uri "/wp-config.inc"] [unique_id "ag4cr8dcc_lsa94icwrLcQAAABE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 193.56.20.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.20.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 14:58:26.062205 2026] [security2:error] [pid 4183:tid 4183] [client 193.56.20.211:15869] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "velvetculture.com"] [uri "/wp-config.txt"] [unique_id "ag4EUqyBPfcUm5j6ZIPjzwAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
mnsf
|
|
Scanning/Probing (24)
|
Brute-Force
Web App Attack
|
|
|
π§πͺ
taivas.nl
|
|
Bad_requests
|
Bad Web Bot
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210350) triggered by 193.56.20.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 193.56.20.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 17 02:56:46.487233 2026] [security2:error] [pid 2839:tid 2839] [client 193.56.20.211:54299] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||coretermite.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "coretermite.com"] [uri "/"] [unique_id "abj7LuPqUrUcioJTxxBYvgAAAAo"], referer: https://www.facebook.com/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π«π·
tilellit.pro
|
|
Fail2Ban banned 193.56.20.211 for security violations in jail wp-armour. Log: 2026/02/06 16:19:15 [e ...
show more
Fail2Ban banned 193.56.20.211 for security violations in jail wp-armour. Log: 2026/02/06 16:19:15 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 193.56.20.211 | Target: wplogin" , client: 193.56.20.211, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
|
Web Spam
|
|
|
π«π·
tilellit.pro
|
|
Fail2Ban banned 193.56.20.211 for security violations in jail wp-armour. Log: 2026/02/04 23:12:03 [e ...
show more
Fail2Ban banned 193.56.20.211 for security violations in jail wp-armour. Log: 2026/02/04 23:12:03 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 193.56.20.211 | Target: wplogin" , client: 193.56.20.211, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
|
Web Spam
|
|
|
π©πͺ
Packets-Decreaser.NET
|
|
Incoming Layer 7 Flood Detected
|
DDoS Attack
Web Spam
|
|
|
πΊπΈ
MrDD
|
|
Brute Force Attack on Cisco Web VPN
|
Brute-Force
|
|
|
Anonymous
|
|
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
|
Web App Attack
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
π©πͺ
niceshops.com
|
|
Web Attack multi (Feb 23 05:12:43 )
|
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
niceshops.com
|
|
Web Attack multi (Feb 23 02:26:51 )
|
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
niceshops.com
|
|
Web Attack multi (Feb 23 03:31:21 )
|
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
|
|