๐บ๐ธ
TPI-Abuse
2026-09-28 15:09:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:09:51.392381 2026] [security2:error] [pid 8273:tid 8273] [client 100.58.4.70:16405] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "folkdancers.org"] [uri "/wp-config.php~"] [unique_id "arqDPzWcQaBr1xLkXDHe3gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 06:00:11
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:59:58.316648 2026] [security2:error] [pid 23576:tid 23576] [client 100.58.4.70:12669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lct.lbee.com"] [uri "/wp-config.php.txt"] [unique_id "aroCXiRqHk_7vOjB-UGRMQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 01:42:16
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 21:42:10.372624 2026] [security2:error] [pid 16703:tid 16703] [client 100.58.4.70:23249] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tigerpathteam.org"] [uri "/wp-config.php~"] [unique_id "arnF8oEF9wIoLwCAiEK_PgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 18:36:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 14:36:32.664304 2026] [security2:error] [pid 682:tid 682] [client 100.58.4.70:37970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.assec.org"] [uri "/wp-config.php.backup"] [unique_id "arliMBf6C65kh3RIGRzChwAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 16:47:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 12:47:15.261518 2026] [security2:error] [pid 2174:tid 2174] [client 100.58.4.70:50189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.scswat.org"] [uri "/wp-config.php.backup"] [unique_id "arlIkzFx0t-gae2MpjN4GwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 16:20:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 12:20:10.988225 2026] [security2:error] [pid 21246:tid 21246] [client 100.58.4.70:31713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.andiamorun.com"] [uri "/wp-config.php.bak"] [unique_id "arlCOp7guH96BPcUdLgq6QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 15:51:43
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210730) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 11:51:35.751819 2026] [security2:error] [pid 1282:tid 1282] [client 100.58.4.70:33036] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||earlyfordv8crrg10.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "earlyfordv8crrg10.com"] [uri "/db.sql"] [unique_id "ark7h_bnOMBR5TaQA8J6dAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 12:13:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 100.58.4.70 (ec2-100-58-4-70.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 08:13:21.906857 2026] [security2:error] [pid 7923:tid 7923] [client 100.58.4.70:4254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hamiltoncountyuca.org"] [uri "/wp-config.php.backup"] [unique_id "arkIYXbIqcRtjRpeLZ2OzgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-25 12:38:01
(3 days ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: / | 2026-09-25 12:38 UTC
show less
Bad Web Bot
๐จ๐ฟ
Countryman
2026-09-22 17:30:03
(6 days ago)
IPS detection: Apache.HTTP.Server.cgi-bin.Path.Traversal
Hacking
๐จ๐ฟ
Countryman
2026-09-22 17:30:03
(6 days ago)
IPS detection: Apache.HTTP.Server.cgi-bin.Path.Traversal
Hacking
Anonymous
2026-09-22 09:25:47
(6 days ago)
denied traffic to a honeypot network. destination port 22.
Port Scan
Hacking
๐ณ๐ด
jad-abuse
2026-09-20 07:20:20
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: cgi_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: cgi_probe. Observed by 1 sensor(s); 1 hits.
show less
Hacking
Web App Attack