๐จ๐ญ
4server
2026-09-15 17:10:59
(1 day ago)
[TueSep1519:10:53.6467322026][security2:error][pid1765722:tid1765848][client51.159.52.121:0]ModSecur ...
show more
[TueSep1519:10:53.6467322026][security2:error][pid1765722:tid1765848][client51.159.52.121:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"4-server.com\"][uri\"/\"][unique_id\"aql8HblxAilwCDR1APVIzgAAANM\"]
show less
Hacking
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-10 22:23:08
(6 days ago)
Brute-Force
Web App Attack
Anonymous
2026-09-10 06:27:21
(1 week ago)
Fail2Ban triggered
Web App Attack
๐บ๐ธ
MPL
2026-09-08 19:47:39
(1 week ago)
tcp ports: 80,443 (8 or more attempts)
Port Scan
๐ซ๐ฎ
wpwoodo
2026-09-08 14:07:28
(1 week ago)
Webpage crawler
Bad Web Bot
๐ฌ๐ง
consul.to
2026-06-08 02:14:52
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
VanKoh
2026-05-24 05:21:46
(3 months ago)
51.159.52.121 - - [23/May/2026:23:21:42 -0600] "GET https://am4digital.xyz/ews/ HTTP/1.1" 301 162 "- ...
show more
51.159.52.121 - - [23/May/2026:23:21:42 -0600] "GET https://am4digital.xyz/ews/ HTTP/1.1" 301 162 "-" "Mozilla/9.0 AppleWebKit/202110.05 (KHTML, like Gecko) Chrome/20.21.1005.122 Safari/211.05"
51.159.52.121 - - [23/May/2026:23:21:42 -0600] "GET https://am4digital.xyz/phpinfo.php HTTP/1.1" 301 162 "-" "Mozilla/9.0 AppleWebKit/202110.05 (KHTML, like Gecko) Chrome/20.21.1005.122 Safari/211.05"
51.159.52.121 - - [23/May/2026:23:21:45 -0600] "GET https://am4digital.xyz/am4digital.xyz.zip HTTP/1.1" 301 162 "-" "Mozilla/9.0 AppleWebKit/202110.05 (KHTML, like Gecko) Chrome/20.21.1005.122 Safari/211.05"
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 04:01:54
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.e ...
show more
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 00:01:47.819640 2026] [security2:error] [pid 16269:tid 16298] [client 51.159.52.121:54946] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kcscomputer.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kcscomputer.com"] [uri "/skins.bak"] [unique_id "ag0yK10SQUMi6Qp35P_r4QAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-05-19 06:36:20
(3 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-06 20:01:26
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.e ...
show more
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 16:01:19.281770 2026] [security2:error] [pid 26008:tid 26008] [client 51.159.52.121:56222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kavahawaii.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kavahawaii.com"] [uri "/wp-config.inc"] [unique_id "afueD4910ptdQAs8pRBe-AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 12:48:48
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.e ...
show more
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 08:48:44.333943 2026] [security2:error] [pid 1305760:tid 1305760] [client 51.159.52.121:33158] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||karendraughon.com|F|2"] [data ".files.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "karendraughon.com"] [uri "/index.files.bak"] [unique_id "ad-JLIEscdgNgERHyEfNBgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 09:58:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.e ...
show more
(mod_security) mod_security (id:210492) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 05:58:43.556101 2026] [security2:error] [pid 1542239:tid 1542239] [client 51.159.52.121:49802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karenbernsteinlaw.net"] [uri "/.wp-config.php.swp"] [unique_id "ad9hU4hxP3NItoz3pv06wAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 23:27:05
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.e ...
show more
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 19:26:58.446141 2026] [security2:error] [pid 26972:tid 26972] [client 51.159.52.121:57204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||k-and-l-contractors.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "k-and-l-contractors.com"] [uri "/ziong.bak"] [unique_id "adLvwkWVrXLp70MqKTUAWwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 14:56:30
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.e ...
show more
(mod_security) mod_security (id:210730) triggered by 51.159.52.121 (51-159-52-121.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 10:56:23.991203 2026] [security2:error] [pid 29954:tid 29954] [client 51.159.52.121:34350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kameleonquilt.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kameleonquilt.com"] [uri "/gallery/index.php.bak"] [unique_id "ac6Dl8pXrgDHCOQA5bNm-gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-03-14 06:58:36
(6 months ago)
11.925 4xx requests in 1 hour (1yr10mos3w)
Brute-Force
Bad Web Bot