Anonymous
2025-04-25 16:34:29
(1 year ago)
Malicious activity detected
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-04-25 16:22:12
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 12:22:07.052356 2025] [security2:error] [pid 22876:tid 22882] [client 162.241.252.86:57788] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psychclinicforchange.com"] [uri "/wp-config.bak"] [unique_id "aAu2r7Bj4_PULXeVdSPj0wAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-25 15:30:05
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 11:30:00.086054 2025] [security2:error] [pid 11399:tid 11399] [client 162.241.252.86:11030] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armadillosigns.com"] [uri "/wp-config.bak"] [unique_id "aAuqeE0WJEnlxD3_WScTFQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-24 19:40:33
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 24 15:40:29.544331 2025] [security2:error] [pid 19439:tid 19439] [client 162.241.252.86:38414] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desarrollosdecolima.com"] [uri "/wp-config.php.backup"] [unique_id "aAqTrUs3JmSbly0_2PRudAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-24 11:02:49
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 24 07:02:44.775226 2025] [security2:error] [pid 11723:tid 11723] [client 162.241.252.86:37404] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karenbernsteinlaw.com"] [uri "/wp-config.php.backup"] [unique_id "aAoaVN54Uqa7tfX__-XubwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 21:53:42
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 17:53:37.310209 2025] [security2:error] [pid 2723500:tid 2723500] [client 162.241.252.86:60668] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mikethehomehelper.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mikethehomehelper.com"] [uri "/wp-config.backup"] [unique_id "aAlhYcQfXqQuX0DCbVlIhwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 20:05:35
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 16:05:29.735157 2025] [security2:error] [pid 22478:tid 22478] [client 162.241.252.86:50462] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daisyweddinginvitations.com"] [uri "/wp-config.php.backup"] [unique_id "aAlICREjbPPiir76S_PfkwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 12:21:21
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 08:21:17.330497 2025] [security2:error] [pid 23223:tid 23223] [client 162.241.252.86:20994] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "electricmeatgrinder.com"] [uri "/wp-config.php.backup"] [unique_id "aAjbPUMXRRWfVvIyVt-OhgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 09:39:14
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 05:39:10.958334 2025] [security2:error] [pid 2786:tid 2786] [client 162.241.252.86:19100] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armrms.com"] [uri "/wp-config.php.backup"] [unique_id "aAi1Pl1OigRF1Wxqii8u2QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 06:23:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 02:23:52.696123 2025] [security2:error] [pid 330198:tid 330198] [client 162.241.252.86:59656] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uppermotradingco.com"] [uri "/wp-config.php.backup"] [unique_id "aAiHeDH3961pTkzLBHwOfQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-04-23 01:19:29
(1 year ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-22 23:47:10
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 19:47:06.548810 2025] [security2:error] [pid 5733:tid 5733] [client 162.241.252.86:57450] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lockyers.com"] [uri "/wp-config.php.old"] [unique_id "aAgqeiwjqcK2sqmyIUNtTAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-22 16:52:25
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 12:52:17.091267 2025] [security2:error] [pid 3632575:tid 3632575] [client 162.241.252.86:35948] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guarinofurnituredesigns.com"] [uri "/wp-config.php.old"] [unique_id "aAfJQTvnfneObXzEewS-MAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-22 15:47:29
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 11:47:25.936211 2025] [security2:error] [pid 14348:tid 14348] [client 162.241.252.86:32832] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cnphilos.com"] [uri "/wp-config.php.old"] [unique_id "aAe6DRLvoBd0GUo5unaL2gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-21 05:02:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.252.86 (box5699.bluehost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 21 01:02:52.800291 2025] [security2:error] [pid 25438:tid 25438] [client 162.241.252.86:52338] [client 162.241.252.86] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.old" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amrtactical.com"] [uri "/wp-config.old"] [unique_id "aAXRfIOWNHbueYct3_ATlwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack