🇧🇪
taivas.nl
2026-09-13 15:32:18
(12 hours ago)
Site scraper
Web App Attack
🇧🇪
taivas.nl
2026-09-13 15:02:12
(12 hours ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 14:28:40
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:28:35.978571 2026] [security2:error] [pid 30955:tid 30955] [client 139.59.31.197:33362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.major33.com.cruanyes.com"] [uri "/wp-config.php.bak"] [unique_id "aqazE6lXLSksE0X6sPq_dgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-13 14:16:03
(13 hours ago)
csagent: score 16.2: wp-config backup grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
Anonymous
2026-09-13 13:46:44
(14 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-13 12:54:00
(15 hours ago)
110 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
🇿🇦
conure.sh
2026-09-13 10:09:50
(17 hours ago)
csagent: score 19.9: wp-config backup grab x2; 1 domain(s) in 2s
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-13 02:13:43
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
🇳🇱
Alt255
2026-09-13 01:11:07
(1 day ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 139.59.31.197 - - [13/Sep/2026:03:11:06 +0200] "GET /.env.swp HTTP/1.1" 301 6090 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 00:02:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:02:26.959237 2026] [security2:error] [pid 11367:tid 11367] [client 139.59.31.197:41058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.splashstation.org"] [uri "/wp-config.php.save"] [unique_id "aqXoEjJQtgKDq4Paj7hRoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:35:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:35:15.627444 2026] [security2:error] [pid 14655:tid 14655] [client 139.59.31.197:32896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "georgegourmet.visionremota.info"] [uri "/wp-config.php.bak"] [unique_id "aqXhsypJRT7KJ3NM6VXAmgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:50:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:50:01.059365 2026] [security2:error] [pid 24639:tid 24639] [client 139.59.31.197:48450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usaenquirer.com.bamedica.com"] [uri "/wp-config.php.txt"] [unique_id "aqXXGUTB9c76Vs1o34F19gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 20:43:42
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-12 18:36:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:36:44.434029 2026] [security2:error] [pid 4029131:tid 4029137] [client 139.59.31.197:41014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.reghay.com"] [uri "/wp-config.php.bak"] [unique_id "aqWbvPh-LEx7p3or0znGagAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 13:40:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.31.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:40:46.491043 2026] [security2:error] [pid 18173:tid 18173] [client 139.59.31.197:58752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/composer.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennyfiore.com"] [uri "/composer.json"] [unique_id "aqVWXoIKRu-XR1I9mN8OVQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack