🇧🇪
taivas.nl
2026-09-08 04:33:19
(15 minutes ago)
Many_bad_calls
Web App Attack
🇪🇸
scaballe
2026-09-08 04:14:06
(34 minutes ago)
Web App Attack
🇩🇪
Tha_14
2026-09-08 04:10:26
(38 minutes ago)
Multiple suspicious activities were detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:29:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.255.225.13 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.255.225.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:29:06.699493 2026] [security2:error] [pid 2842429:tid 2842429] [client 104.255.225.13:54238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joevallone.taxgroupsd.com"] [uri "/wp-config.php.bak"] [unique_id "ap-BAi44XXS-vBsYrIuc9QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:06:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.255.225.13 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.255.225.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:06:07.306414 2026] [security2:error] [pid 8929:tid 8929] [client 104.255.225.13:47194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "femalegamblers.org"] [uri "/wp-config.php.bak"] [unique_id "ap97nxIG6M-q7l37qkvmLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:37:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.255.225.13 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.255.225.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:37:28.624919 2026] [security2:error] [pid 861067:tid 861076] [client 104.255.225.13:43210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.reghay.com"] [uri "/wp-config.php.bak"] [unique_id "ap906Pauu5gs53CK6bxKrgAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-08 02:35:16
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-08 02:34:41
(2 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-08 02:11:56
(2 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇭🇺
bcsaba
2026-09-08 01:40:58
(3 hours ago)
Looking for wp-config backup
104.255.225.13 - - [08/Sep/2026:03:40:56 +0200] "GET /wp-config.php~ HT ...
show more
Looking for wp-config backup
104.255.225.13 - - [08/Sep/2026:03:40:56 +0200] "GET /wp-config.php~ HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack
🇧🇷
dominioz
2026-09-08 01:27:01
(3 hours ago)
2026-09-08 01:26:24 POST / rest_route=/batch/v1 - 104.255.225.13 HTTP/1.1 Mozilla/5.0+(Windows+NT+10 ...
show more
2026-09-08 01:26:24 POST / rest_route=/batch/v1 - 104.255.225.13 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 403 558
2026-09-08 01:26:24 POST /wp-json/batch/v1 - - 104.255.225.13 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 403 558
2026-09-08 01:26:26 POST /index.php rest_route=/batch/v1 - 104.255.225.13 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 403 558
2026-09-08 01:26:26 POST /index.php/wp-json/batch/v1 - - 104.255.225.13 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 403 558
...
show less
Web App Attack
Anonymous
2026-09-08 01:24:11
(3 hours ago)
WordPress Gravity SMTP Plugin Information Disclosure (CVE-2026-4020).
Hacking
🇬🇧
thetomtaylor.co.uk
2026-09-08 01:12:02
(3 hours ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:08:03
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.255.225.13 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.255.225.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:07:54.400144 2026] [security2:error] [pid 17805:tid 17805] [client 104.255.225.13:48538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pcga.golf"] [uri "/wp-config.php.bak"] [unique_id "ap9f6sxQshKsDdf2-8MB3QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
thezelijah
2026-09-08 00:45:56
(4 hours ago)
[AI Threat Score: 100/100 via Gemini] [AbuseIPDB Score: 100] The IP address 104.255.225.13 generated ...
show more
[AI Threat Score: 100/100 via Gemini] [AbuseIPDB Score: 100] The IP address 104.255.225.13 generated a local hit requesting the root endpoint GET /, which triggered a nonexistent-endpoint rule. This localized activity aligns with an AbuseIPDB reputation showing an absolute confidence score of 100 percent and 23 total external reports, with the most recent external report occurring just minutes after the local observation. Likely motive: Automated scanning and malicious probing
show less
Hacking
Web App Attack
Port Scan