๐บ๐ธ
TPI-Abuse
2026-07-25 15:49:56
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 20.251.160.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 20.251.160.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 11:49:50.807320 2026] [security2:error] [pid 2740701:tid 2740701] [client 20.251.160.16:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||colonybet.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "colonybet.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amTbHut7JyTwceQeS3rRrgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 15:39:30
(11 hours ago)
Automatically blocked after 1 security event. Observed PHPUnit exploit probes. Source: Cloudflare se ...
show more
Automatically blocked after 1 security event. Observed PHPUnit exploit probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
๐ฉ๐ช
maxpower
2026-07-25 14:09:58
(12 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.251.160.16 (NO/Norway/-): 1 in the la ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.251.160.16 (NO/Norway/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.251.160.16 - - [25/Jul/2026:16:09:30 +0200] "GET //vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0" "20.251.160.16" host=marialauracaselli.com
show less
Port Scan
๐ฌ๐ง
Aetherweb Ark
2026-07-25 12:12:40
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 20.251.160.16 (NO/Norway/-): N in the last X se ...
show more
(mod_security) mod_security (id:949110) triggered by 20.251.160.16 (NO/Norway/-): N in the last X secs
show less
Web App Attack
๐ซ๐ฎ
pixiekat
2026-07-25 10:44:17
(16 hours ago)
[Sat Jul 25 11:43:42.060212 2026] [security2:error] [pid 2106667:tid 2106736] [client 20.251.160.16: ...
show more
[Sat Jul 25 11:43:42.060212 2026] [security2:error] [pid 2106667:tid 2106736] [client 20.251.160.16:57557] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.28.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "integraldata.cc"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amSTXinGz7kPGqWalh7cRwAAAIk"]
[Sat Jul 25 11:44:08.430874 2026] [security2:error] [pid 2106667:tid 2106747] [client 20.251.160.16:62196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.28.0"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 10:02:17
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 20.251.160.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 20.251.160.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 06:02:12.614495 2026] [security2:error] [pid 19360:tid 19360] [client 20.251.160.16:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||yggdrasil.org|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "yggdrasil.org"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amSJpLopN3ZdxINbaHLxvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 09:10:27
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 20.251.160.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 20.251.160.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 05:10:21.383300 2026] [security2:error] [pid 2100970:tid 2100970] [client 20.251.160.16:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rodrigoaldecoa.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rodrigoaldecoa.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amR9fRdOvAok3tq28QG3wQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-07-25 04:39:08
(22 hours ago)
[ISILIA Protection v2.1] Tentative d'accรจs: //vendor/phpunit/phpunit/phpunit.xsd | Pays: NO | UA: Mo ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: //vendor/phpunit/phpunit/phpunit.xsd | Pays: NO | UA: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
show less
Hacking
Web App Attack
๐ญ๐ฐ
Mehmet_The_Script_Kiddie
2026-07-25 02:54:38
(1 day ago)
AUTOMATED REPORT: Vulnerability scan - PHPUnit vulnerabilities: //vendor/phpunit/phpunit/phpunit.xsd
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 02:24:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 20.251.160.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 20.251.160.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:24:38.588427 2026] [security2:error] [pid 555188:tid 555188] [client 20.251.160.16:55070] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cooteconsultinggroup.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cooteconsultinggroup.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amQeZmIdzo8HUnp8RX27TgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-07-25 01:54:26
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.251.160.16 (NO/Norway/-): 1 in the la ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.251.160.16 (NO/Norway/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.251.160.16 - - [25/Jul/2026:03:54:22 +0200] "GET //vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0" "20.251.160.16" host=digiampaolosrl.it
show less
Port Scan
๐ฉ๐ช
maxpower
2026-07-25 00:03:21
(1 day ago)
(PERMBLOCK) 20.251.160.16 (NO/Norway/-) has had more than 4 temp blocks in the last 86400 secs; Port ...
show more
(PERMBLOCK) 20.251.160.16 (NO/Norway/-) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
Anonymous
2026-07-24 23:04:26
(1 day ago)
20.251.160.16 - - [24/Jul/2026:06:38:20 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 40 ...
show more
20.251.160.16 - - [24/Jul/2026:06:38:20 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 12927 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
20.251.160.16 - - [24/Jul/2026:23:03:17 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 12927 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
20.251.160.16 - - [24/Jul/2026:23:03:42 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 12927 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
20.251.160.16 - - [24/Jul/2026:23:04:03 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 12927 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
20.251.160.16 - - [24/Jul/2026:23:04:23 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 404 12927 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
...
show less
Brute-Force
Web App Attack
๐ท๐บ
Reaper
2026-07-24 22:47:51
(1 day ago)
GET //vendor/phpunit/phpunit/phpunit.xsd
Web App Attack
๐ฉ๐ช
maxpower
2026-07-24 21:54:47
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.251.160.16 (NO/Norway/-): 1 in the la ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.251.160.16 (NO/Norway/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.251.160.16 - - [24/Jul/2026:23:54:46 +0200] "GET //vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0" "20.251.160.16" host=italpmiabruzzo.it
show less
Port Scan