🇲🇾
Rizzy
2026-09-07 22:53:51
(14 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-07 22:06:46
(14 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇦🇺
2000cn.com.au
2026-09-07 22:01:02
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 21:42:29
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 102.213.120.210 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.213.120.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:42:23.820512 2026] [security2:error] [pid 19620:tid 19620] [client 102.213.120.210:58628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newhopepetgrooming.com"] [uri "/wp-config.php.bak"] [unique_id "ap8vv2wGJ73U27iIYAeO3wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 21:10:03
(15 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:54:16
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 102.213.120.210 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.213.120.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:54:11.006280 2026] [security2:error] [pid 2398628:tid 2398628] [client 102.213.120.210:41008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "williamfitzsimmons.com"] [uri "/wp-config.php.bak"] [unique_id "ap8kc9nFYK44DZTRIQY6tQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 19:43:26
(17 hours ago)
238 requests with url.path *.php.bak
111 requests with url.path *debug.log
111 requests with url. ...
show more
238 requests with url.path *.php.bak
111 requests with url.path *debug.log
111 requests with url.path */debug.log
show less
Brute-Force
Bad Web Bot
🇷🇴
iulianh
2026-09-07 19:33:45
(17 hours ago)
80,443
Brute-Force
SSH
🇮🇹
VHosting
2026-09-07 19:15:03
(17 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-07 19:14:58
(17 hours ago)
FPROCO WEBEXPLOIT 102.213.120.210 (102.213.120.210)
Web App Attack
🇫🇷
dynamix
2026-09-07 19:08:13
(17 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:07:16
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 102.213.120.210 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.213.120.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:07:09.931521 2026] [security2:error] [pid 19793:tid 19810] [client 102.213.120.210:48488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.whitecrosslibrary.aafm.us"] [uri "/wp-config.php.bak"] [unique_id "ap8LXYMT5RobvYSQfLGdWQAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
soc-yk
2026-09-07 19:06:17
(17 hours ago)
Type: suspicious_network_activity
Risk: 71
Events: 46
Evidence:
- Persistent suspicious network act ...
show more
Type: suspicious_network_activity
Risk: 71
Events: 46
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Threat escalation behavior observed
show less
Port Scan
Hacking
🇺🇸
TAY
2026-09-07 18:59:57
(17 hours ago)
102.213.120.210 - - [08/Sep/2026:02:59:31 +0800] "GET /wp-config.php~ HTTP/1.1" 404 54940 "-" "Mozil ...
show more
102.213.120.210 - - [08/Sep/2026:02:59:31 +0800] "GET /wp-config.php~ HTTP/1.1" 404 54940 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
102.213.120.210 - - [08/Sep/2026:02:59:36 +0800] "GET /wp-config.php.save HTTP/1.1" 404 54944 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
102.213.120.210 - - [08/Sep/2026:02:59:38 +0800] "GET /wp-config.php.old HTTP/1.1" 404 54943 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
102.213.120.210 - - [08/Sep/2026:02:59:41 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 54966 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
102.213.120.210 - - [08/Sep/2026:02:59:53 +0800] "GET /wp-config.php.txt HTTP/1.1" 404 54943 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3
...
show less
Brute-Force
🇬🇧
poundawebsiteltd
2026-06-11 08:35:58
(2 months ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:80 102.213.120.210 - - [11/Jun/2026: ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:80 102.213.120.210 - - [11/Jun/2026:09:35:56 +0100] POST / HTTP/1.1 403 158 - Mozilla/5.0
show less
Web App Attack