🇸🇪
vaia.cloud
2026-09-12 22:35:02
(33 minutes ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:18:08
(50 minutes ago)
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:18:03.792888 2026] [security2:error] [pid 1896:tid 1896] [client 158.220.89.244:56330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theamarals.com"] [uri "/wp-config.php~"] [unique_id "aqXPm-OYROtwQZ8BndYzZQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
VanKoh
2026-09-12 19:20:19
(3 hours ago)
158.220.89.244 - - [12/Sep/2026:13:19:40 -0600] "GET /wp-config.php.old HTTP/1.1" 444 0 "-" "Mozilla ...
show more
158.220.89.244 - - [12/Sep/2026:13:19:40 -0600] "GET /wp-config.php.old HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
158.220.89.244 - - [12/Sep/2026:13:20:17 -0600] "GET /wp-config.php.txt HTTP/1.1" 404 58296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
158.220.89.244 - - [12/Sep/2026:13:20:18 -0600] "GET /wp-config.php.swp HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-09-12 19:18:25
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
MPL
2026-09-12 18:26:58
(4 hours ago)
tcp ports: 80,443 (32 or more attempts)
Port Scan
🇺🇸
TPI-Abuse
2026-09-12 17:18:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 13:18:28.232286 2026] [security2:error] [pid 23939:tid 23983] [client 158.220.89.244:33136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vinylnotespodcast.com"] [uri "/wp-config.php~"] [unique_id "aqWJZAfHYoBr1JkWgLdL2wAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-12 15:17:00
(7 hours ago)
*Port Scan* detected from 158.220.89.244 (GB/United Kingdom/vmi1656937.contaboserver.net). 11 hits i ...
show more
*Port Scan* detected from 158.220.89.244 (GB/United Kingdom/vmi1656937.contaboserver.net). 11 hits in the last 80 seconds (0-195)
show less
Port Scan
Anonymous
2026-09-12 15:04:07
(8 hours ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.iatrika-analosima.gr; logs=/var/log/httpd/domains/ia ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.iatrika-analosima.gr; logs=/var/log/httpd/domains/iatrika-analosima.gr.log; samples=/wp-config.php~
show less
Hacking
Web App Attack
🇺🇸
ambor
2026-09-12 12:18:03
(10 hours ago)
Attack type: wordpress_attack_attempt | Target: /api/session/properties | UA: metabase-cve-2026-7289 ...
show more
Attack type: wordpress_attack_attempt | Target: /api/session/properties | UA: metabase-cve-2026-72898-detect/1.0 (benign detecti | Country: GB
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-12 12:08:20
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:08:15.740723 2026] [security2:error] [pid 19064:tid 19064] [client 158.220.89.244:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ndanetworks.com"] [uri "/.env"] [unique_id "aqVAr2Ju-I6TWlyx52r21AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-12 12:06:35
(11 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇱
Alt255
2026-09-12 11:55:06
(11 hours ago)
158.220.89.244 - - [12/Sep/2026:13:55:05 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 57614 "-" "Moz ...
show more
158.220.89.244 - - [12/Sep/2026:13:55:05 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 57614 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:29:45
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:29:41.132552 2026] [security2:error] [pid 8236:tid 8236] [client 158.220.89.244:46880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thereisaplaceonearth.com"] [uri "/wp-config.php.bak"] [unique_id "aqU3pfJhkDDtIdLkH8nxLgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:10:23
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:10:16.648471 2026] [security2:error] [pid 21236:tid 21236] [client 158.220.89.244:46830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulsingdahlsen.com"] [uri "/wp-config.php~"] [unique_id "aqUzGPZkpBoUQetSZll0CAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:50:41
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 158.220.89.244 (vmi1656937.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:50:35.146280 2026] [security2:error] [pid 8922:tid 8922] [client 158.220.89.244:50956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bikinitweets.com"] [uri "/wp-config.php.orig"] [unique_id "aqUgayq3HdoEMbf3hoJxrwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack