🇫🇷
SpaceHost-Server
2026-09-08 22:15:57
(17 hours ago)
Brute-Force
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-08 11:46:04
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TAY
2026-09-08 11:27:14
(1 day ago)
156.67.110.109 - - [08/Sep/2026:19:26:57 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 474 "-" "Mozil ...
show more
156.67.110.109 - - [08/Sep/2026:19:26:57 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 474 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.67.110.109 - - [08/Sep/2026:19:27:01 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6144 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.67.110.109 - - [08/Sep/2026:19:27:03 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 72066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.67.110.109 - - [08/Sep/2026:19:27:07 +0800] "GET /wp-config.php~ HTTP/1.1" 301 468 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.67.110.109 - - [08/Sep/2026:19:27:10 +0800] "GET /wp-config.php~ HTTP/1.1" 301 6141 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like G
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 10:38:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 156.67.110.109 (vmi3019872.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 156.67.110.109 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:38:54.350102 2026] [security2:error] [pid 1536:tid 1536] [client 156.67.110.109:40006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fgrotary.org"] [uri "/wp-config.php.old"] [unique_id "ap_lvqW1hr1G5-O6w4cCEwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:16:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 156.67.110.109 (vmi3019872.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 156.67.110.109 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:16:39.563342 2026] [security2:error] [pid 4620:tid 4620] [client 156.67.110.109:60000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "susanleeward.com"] [uri "/wp-config.php~"] [unique_id "ap_gh1Re9TeQ71-JcPLFPwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 10:01:37
(1 day ago)
Fail2Ban triggered
Web App Attack
🇲🇾
Rizzy
2026-09-08 09:00:25
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-08 08:35:36
(1 day ago)
TACHIDE WEBEXPLOIT 156.67.110.109 (vmi3019872.contaboserver.net)
Web App Attack
🇦🇺
2000cn.com.au
2026-09-08 08:34:57
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-probing
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-08 08:23:28
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:59:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 156.67.110.109 (vmi3019872.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 156.67.110.109 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:59:15.878408 2026] [security2:error] [pid 25043:tid 25043] [client 156.67.110.109:49440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hydrometal-js.com"] [uri "/wp-config.php~"] [unique_id "ap_AU4ES2m3XiFB3nz0cPwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:28:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 156.67.110.109 (vmi3019872.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 156.67.110.109 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:27:57.968960 2026] [security2:error] [pid 28236:tid 28254] [client 156.67.110.109:36772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vinylnotespodcast.com"] [uri "/wp-config.php~"] [unique_id "ap-q7ZLBcaqXsEhfTGsFuQAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 04:29:03
(1 day ago)
156.67.110.109 - [07/Sep/2026:21:26:10 -0700] audiobookshelf.koselig.dynu.net "GET /wp-json/gravitys ...
show more
156.67.110.109 - [07/Sep/2026:21:26:10 -0700] audiobookshelf.koselig.dynu.net "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 4564
156.67.110.109 - [07/Sep/2026:21:26:41 -0700] audiobookshelf.koselig.dynu.net "GET /index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 4536
156.67.110.109 - [07/Sep/2026:21:26:56 -0700] audiobookshelf.koselig.dynu.net "GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1" 404 4565
156.67.110.109 - [07/Sep/2026:21:27:28 -0700] audiobookshelf.koselig.dynu.net "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 4565
156.67.110.109 - [07/Sep/2026:21:29:03 -0700] audiobookshelf.koselig.dynu.net "GET /index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 4536
...
show less
Web App Attack
🇪🇸
Francisco Vallejo
2026-09-08 04:27:05
(1 day ago)
[Tue Sep 08 06:26:39.939327 2026] [authz_core:error] [pid 2887594:tid 125406577411776] [client 156.6 ...
show more
[Tue Sep 08 06:26:39.939327 2026] [authz_core:error] [pid 2887594:tid 125406577411776] [client 156.67.110.109:44134] AH01630: client denied by server configuration: proxy:http://localhost:9000/wp-json/gravitysmtp/v1/tests/mock-data
[Tue Sep 08 06:26:43.550972 2026] [authz_core:error] [pid 2887595:tid 125406644520640] [client 156.67.110.109:44146] AH01630: client denied by server configuration: proxy:http://localhost:9000/
[Tue Sep 08 06:26:46.077687 2026] [authz_core:error] [pid 2887594:tid 125406921348800] [client 156.67.110.109:60178] AH01630: client denied by server configuration: proxy:http://localhost:9000/index.php
[Tue Sep 08 06:26:48.621388 2026] [authz_core:error] [pid 2887594:tid 125405847606976] [client 156.67.110.109:60184] AH01630: client denied by server configuration: proxy:http://localhost:9000/wp-json/gravitysmtp/v1/tests/mock-data
[Tue Sep 08 06:27:04.756763 2026] [authz_core:error] [pid 2887594:tid 125405864392384] [client 156.67.110.109:48436] AH01630: client denied
...
show less
Brute-Force
SSH
🇫🇷
solution.it
2026-09-07 21:52:17
(1 day ago)
[Mon Sep 07 23:52:16.840370 2026] [php7:error] [pid 2535:tid 2535] [client 156.67.110.109:39444] scr ...
show more
[Mon Sep 07 23:52:16.840370 2026] [php7:error] [pid 2535:tid 2535] [client 156.67.110.109:39444] script '/var/www/html/blog.solution.it/phpinfo.php' not found or unable to stat
show less
Web App Attack