๐ง๐ช
cmbplf
2026-08-23 08:29:43
(7 hours ago)
157 requests with url.path *.php.bak
100 requests with url.path *config.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
LRob
2026-08-23 07:07:25
(8 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+15 more)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 04:53:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 00:52:53.035229 2026] [security2:error] [pid 12936:tid 12936] [client 128.127.105.151:57338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.texaslawman.net"] [uri "/wp-config.php.txt"] [unique_id "aop8pUJh-a_8bJ_CimwMvAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 03:37:21
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:37:15.789264 2026] [security2:error] [pid 18176:tid 18176] [client 128.127.105.151:54536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stinsonbeachsurfandkayak.com"] [uri "/wp-config.php.dist"] [unique_id "aopq63c5lWW6Zz8gJLFqcwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 03:04:24
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:04:16.904130 2026] [security2:error] [pid 6444:tid 6444] [client 128.127.105.151:52552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.soundtrax.net"] [uri "/wp-config.php"] [unique_id "aopjMLWwl639TttuVIx0fQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-23 01:25:12
(14 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 22:13:04
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 18:12:58.775117 2026] [security2:error] [pid 16726:tid 16726] [client 128.127.105.151:57388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.peterjohnsonauthor.com"] [uri "/wp-config.php.inc"] [unique_id "aooe6sVtDSvf1zpKbkW6tAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 19:43:01
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:42:55.850296 2026] [security2:error] [pid 31821:tid 31821] [client 128.127.105.151:38744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myersbarnescpa.com"] [uri "/.wp-config.php.swp"] [unique_id "aon7v7dMTbZPmj7RKqe9jgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:08:06
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:07:57.774333 2026] [security2:error] [pid 20322:tid 20322] [client 128.127.105.151:45698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.loriarsenault.com"] [uri "/wp-config.php.txt"] [unique_id "aonXbXG2U6myW-aeRjSLZgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-08-22 15:54:05
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 5 in ...
show more
(mod_security) mod_security (id:210492) triggered by 128.127.105.151 (swe-net-ip.as51430.net): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
Anonymous
2026-08-22 15:25:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /cloudflare.ini HTTP/1.1, GET /wordpress/wp-config.php.o ...
show more
Bot / scanning and/or hacking attempts: GET /cloudflare.ini HTTP/1.1, GET /wordpress/wp-config.php.old HTTP/1.1, GET /.env.backup HTTP/1.1, GET /cloudflare.py HTTP/1.1, GET /.cloudflare/config HTTP/1.1, GET /.env.development HTTP/1.1, GET /.env.old HTTP/1.1, GET /_wpeprivate/config.json HTTP/1.1, GET /home/kleintjepils-WORDPRESS.txt HTTP/1.1, GET /wp-config.backup HTTP/1.1, GET /common/config.php.new HTTP/1.1, GET /.env HTTP/1.1, GET /config.php.tar.gz HTTP/1.1, GET /.env~ HTTP/1.1, GET /wordpress/wp-config.php.bak HTTP/1.1, GET /.env.save HTTP/1.1, GET /wordpress/wp-config.php~ HTTP/1.1, GET /wp-config.php.OLD HTTP/1.1, GET /wp-config-sample.php HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.swp HTTP/1.1, GET /config.php.zip HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
maxpower
2026-08-22 14:27:29
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 128.127.105.151 (swe-net-ip.as51430.net) ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 128.127.105.151 (swe-net-ip.as51430.net): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 128.127.105.151 - - [22/Aug/2026:16:27:25 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" "-" host=www.johnfante.org
show less
Port Scan
๐ซ๐ท
dynamix
2026-08-22 13:24:35
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mw
2026-08-16 00:00:22
(1 week ago)
GET /wp-admin/admin-post.php?page=pb_backupbuddy_destinations&local-destination-id=/etc/passwd&local ...
show more
GET /wp-admin/admin-post.php?page=pb_backupbuddy_destinations&local-destination-id=/etc/passwd&local-download=/etc/passwd HTTP/1.1
show less
Web App Attack
๐ฎ๐ฑ
spd.co.il
2026-08-14 14:02:01
(1 week ago)
Web application attack detected
Hacking
Web App Attack