🇯🇵
weils.net
2026-09-04 05:01:34
(9 hours ago)
2026-09-04 13:01:33(GMT+8) - /administrator.php
Bad Web Bot
🇺🇸
Lee Daniel
2026-09-04 04:39:53
(9 hours ago)
139.162.27.63 - - [04/Sep/2026:00:39:53 -0400] "GET /c99.php HTTP/1.1" 403 6294 "-" "Mozilla/5.0 (Li ...
show more
139.162.27.63 - - [04/Sep/2026:00:39:53 -0400] "GET /c99.php HTTP/1.1" 403 6294 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:39:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:38:55.481436 2026] [security2:error] [pid 15445:tid 15445] [client 139.162.27.63:58711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anus.net"] [uri "/wp-config.php"] [unique_id "apo9T8dG8sYP1qAPnOzj7gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-03 19:05:20
(19 hours ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 13:19:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:19:02.797746 2026] [security2:error] [pid 21301:tid 21301] [client 139.162.27.63:63098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aquatreat.net"] [uri "/wp-config.php"] [unique_id "aplzxnB0XAbrwqEs4CgKdwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 06:49:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:49:15.676741 2026] [security2:error] [pid 24859:tid 24859] [client 139.162.27.63:59197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "celltechs.net"] [uri "/wp-config.php"] [unique_id "apkYa8C8aLwt7BweWsSO5gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-09-03 04:47:48
(1 day ago)
Web App Attack
Web App Attack
🇫🇷
dynamix
2026-09-03 00:30:06
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-02 12:20:13
(2 days ago)
139.162.27.63 - - [02/Sep/2026:12:20:13 +0000] "GET /wp-content/install.php HTTP/1.1" 302 528 "-" "M ...
show more
139.162.27.63 - - [02/Sep/2026:12:20:13 +0000] "GET /wp-content/install.php HTTP/1.1" 302 528 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
139.162.27.63 - - [02/Sep/2026:12:20:13 +0000] "GET /wp-admin/user/about.php HTTP/1.1" 302 530 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
139.162.27.63 - - [02/Sep/2026:12:20:13 +0000] "GET /wp-includes/install.ph
...
show less
Web App Attack
🇺🇸
monn45888
2026-09-02 07:21:38
(2 days ago)
$f2bV_matches
Web App Attack
🇫🇷
dynamix
2026-09-01 22:47:31
(2 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 21:59:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:59:07.522381 2026] [security2:error] [pid 12060:tid 12060] [client 139.162.27.63:51436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baird.net"] [uri "/wp-config.php"] [unique_id "apdKq51r-3uSgy6d78neogAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nyt
2026-09-01 04:35:54
(3 days ago)
Hacking, Web App Attack, suspicious: Web Shell Upload
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 03:46:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.63 (139-162-27-63.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:45:55.807354 2026] [security2:error] [pid 13685:tid 13685] [client 139.162.27.63:54081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glamorgirl.net"] [uri "/wp-config.php"] [unique_id "apZKc3sDay3C0lY3AdqOVgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-01 00:57:04
(3 days ago)
Scanning for web/db/file exploits on www.kerstpakket.net
SQL Injection
Bad Web Bot
Web App Attack