🇬🇧
thetomtaylor.co.uk
2026-09-08 11:08:01
(14 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa02]
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:13:44
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): ...
show more
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:13:39.586757 2026] [security2:error] [pid 1671:tid 1671] [client 121.79.66.127:40812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eta-mct.com"] [uri "/wp-config.php.old"] [unique_id "ap_f05hjPuIlt6jTgs5dRgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-08 10:05:04
(15 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01]
Hacking
SQL Injection
Web App Attack
🇺🇸
VanKoh
2026-09-08 09:56:14
(15 hours ago)
121.79.66.127 - - [08/Sep/2026:03:56:09 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Mozilla/ ...
show more
121.79.66.127 - - [08/Sep/2026:03:56:09 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
121.79.66.127 - - [08/Sep/2026:03:56:11 -0600] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
121.79.66.127 - - [08/Sep/2026:03:56:12 -0600] "GET /wp-config.php.save HTTP/1.1" 404 58296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web App Attack
🇺🇸
Rip
2026-09-08 08:12:30
(16 hours ago)
WordPress fingerprinting and attack surface probing
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:10:41
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): ...
show more
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:10:34.932544 2026] [security2:error] [pid 3722:tid 3722] [client 121.79.66.127:36646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sharawi-gum.com"] [uri "/wp-config.php.bak"] [unique_id "ap_C-i5AxqK2JFrqnBKJ5QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ITSNF
2026-09-08 08:00:06
(17 hours ago)
Blocked by os-abuseipdb; 8 hits, proto=tcp, ports=443
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-08 07:54:44
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): ...
show more
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:54:38.054504 2026] [security2:error] [pid 4423:tid 4423] [client 121.79.66.127:46100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gasoilliquidsdaily.com"] [uri "/.svn/entries"] [unique_id "ap-_PjYzLgYze3RgPO9ragAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:34:31
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): ...
show more
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:34:26.060814 2026] [security2:error] [pid 26781:tid 26781] [client 121.79.66.127:33893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desdier.com"] [uri "/.git/HEAD"] [unique_id "ap-6glCC0HUWS9XxPokjogAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:11:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): ...
show more
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:11:15.061610 2026] [security2:error] [pid 3529:tid 3529] [client 121.79.66.127:42800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michelehoop.com"] [uri "/wp-config.php.bak"] [unique_id "ap-1E_SYLtHKrNtt1XMpnAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:48:56
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): ...
show more
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:48:52.855446 2026] [security2:error] [pid 20554:tid 20686] [client 121.79.66.127:39743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.councilofforeignministers.aafm.us"] [uri "/wp-config.php.orig"] [unique_id "ap-v1BSsimFmlQ4Ny4HJHwAAApI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 06:36:39
(18 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.traditionalstonehousemani.gr; logs=/var/log/httpd/domain ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.traditionalstonehousemani.gr; logs=/var/log/httpd/domains/traditionalstonehousemani.gr.log; samples=/.env.old
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:17:44
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): ...
show more
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:17:40.082647 2026] [security2:error] [pid 27184:tid 27184] [client 121.79.66.127:43582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brazilianbottom.com"] [uri "/.hg/store/00manifest.i"] [unique_id "ap-ohDWdSX_bdSL8MDfnTAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
ISPLtd
2026-09-08 05:54:03
(19 hours ago)
121.79.66.127 - - [08/Sep/2026:02:53:59 -0300] "GET /wp-content/plugins/wp-mail-bank/
121.79.66.127 ...
show more
121.79.66.127 - - [08/Sep/2026:02:53:59 -0300] "GET /wp-content/plugins/wp-mail-bank/
121.79.66.127 - - [08/Sep/2026:02:54:02 -0300] "GET /wp-content/plugins/gemini/
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:53:41
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): ...
show more
(mod_security) mod_security (id:210492) triggered by 121.79.66.127 (121-79-66-127.sta.ip.vocus.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:53:35.442183 2026] [security2:error] [pid 5572:tid 5572] [client 121.79.66.127:48419] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oliverhardy.com"] [uri "/.env"] [unique_id "ap-i35a0GtpJDAfZJrVaugAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack