🇩🇪
iNetWorker
2026-09-08 07:03:45
(3 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇩🇪
raph
2026-09-08 03:19:18
(7 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:01:53
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.28.144.217 (149.28.144.217.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 149.28.144.217 (149.28.144.217.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:01:46.534012 2026] [security2:error] [pid 6293:tid 6293] [client 149.28.144.217:59584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desdier.com"] [uri "/wp-config.php.save"] [unique_id "ap96moqSxAwS3iFDVB0F7QAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:18:18
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.28.144.217 (149.28.144.217.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 149.28.144.217 (149.28.144.217.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:18:10.264194 2026] [security2:error] [pid 22786:tid 22786] [client 149.28.144.217:60546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orcastrong.com"] [uri "/wp-config.php~"] [unique_id "ap9wYoly4aGbMgxEIcjhMgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 23:34:49
(10 hours ago)
149.28.144.217 - - [07/Sep/2026:20:34:46 -0300] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gr ...
show more
149.28.144.217 - - [07/Sep/2026:20:34:46 -0300] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
149.28.144.217 - - [07/Sep/2026:20:34:47 -0300] "GET /?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
149.28.144.217 - - [07/Sep/2026:20:34:48 -0300] "GET /index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Port Scan
🇩🇪
louis77
2026-09-07 23:32:11
(10 hours ago)
PHP application attack attempt - Path: /index.php, Method: GET, UA: Mozilla/5.0 (Windows NT 10.0; Wi ...
show more
PHP application attack attempt - Path: /index.php, Method: GET, UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Web App Attack
Anonymous
2026-09-07 22:20:32
(12 hours ago)
ANFRADE WEBEXPLOIT 149.28.144.217 (149.28.144.217.vultrusercontent.com)
Web App Attack
🇺🇸
TAY
2026-09-07 19:05:10
(15 hours ago)
149.28.144.217 - - [08/Sep/2026:03:04:13 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 46464 "-" "Moz ...
show more
149.28.144.217 - - [08/Sep/2026:03:04:13 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 46464 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
149.28.144.217 - - [08/Sep/2026:03:04:24 +0800] "GET /wp-config.php~ HTTP/1.1" 404 46464 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
149.28.144.217 - - [08/Sep/2026:03:04:34 +0800] "GET /wp-config.php.save HTTP/1.1" 404 46464 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
149.28.144.217 - - [08/Sep/2026:03:04:45 +0800] "GET /wp-config.php.old HTTP/1.1" 404 46536 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
149.28.144.217 - - [08/Sep/2026:03:04:58 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 46464 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KH
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 18:58:22
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.28.144.217 (149.28.144.217.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 149.28.144.217 (149.28.144.217.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:58:15.579300 2026] [security2:error] [pid 30744:tid 30744] [client 149.28.144.217:53938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.batesstrategygroup.com"] [uri "/wp-config.php~"] [unique_id "ap8JR7IT1dMImYmPDlw1vAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-07 17:31:46
(16 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 76>=65, Abuse 83, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
🇧🇪
cmbplf
2026-09-07 16:58:17
(17 hours ago)
138 requests with url.path *debug.log
134 requests with url.path */debug.log
Brute-Force
Bad Web Bot
🇦🇺
2000cn.com.au
2026-09-07 16:37:42
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇲🇾
Rizzy
2026-09-07 14:53:09
(19 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:53:47
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.28.144.217 (149.28.144.217.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 149.28.144.217 (149.28.144.217.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:53:41.308991 2026] [security2:error] [pid 5015:tid 5015] [client 149.28.144.217:46284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "femalegamblers.mobileonlinecasinos.co"] [uri "/wp-config.php~"] [unique_id "ap6z1d9RLhUggz0AI60cswAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
i-turnradio.nl
2026-09-07 12:38:56
(21 hours ago)
2026-09-07 @ 14:38:41 (CET) ~ Blocked for trying to access: /wp-json/gravitysmtp/v1/tests/mock-data? ...
show more
2026-09-07 @ 14:38:41 (CET) ~ Blocked for trying to access: /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
show less
Web App Attack