๐บ๐ธ
TPI-Abuse
2026-09-25 10:18:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:18:30.593433 2026] [security2:error] [pid 682:tid 682] [client 162.241.63.11:47898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ialenti.com"] [uri "/.env"] [unique_id "arZKdqek_KB_b4K-bz3Q3AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-25 10:08:00
(3 days ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,ice02,wa01,wa02]
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 09:30:02
(4 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 09:02:05
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 05:01:57.710138 2026] [security2:error] [pid 18703:tid 18703] [client 162.241.63.11:30434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "midwayisland.com"] [uri "/.env"] [unique_id "arY4hb21Yq25f24UeX0PHQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 08:17:33
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 04:17:27.220720 2026] [security2:error] [pid 32760:tid 32760] [client 162.241.63.11:57838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canonflorida.com"] [uri "/.env"] [unique_id "arYuFyu7LpcV4bQFtl8xKgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-25 06:52:15
(4 days ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 162.241.63.11 - - [25/Sep/2026:08:52:13 +0200] "GET /.env HTTP/1.1" 301 550 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-23 00:14:53
(6 days ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /wp-config.php.bak | 2026-09-23 00:14 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:19:04
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:18:57.436232 2026] [security2:error] [pid 4469:tid 4469] [client 162.241.63.11:58654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanmetermailing.com"] [uri "/wp-config.php.bak"] [unique_id "arLUoQzqRIj_0pwbbMO5AQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 18:18:53
(6 days ago)
[elearning.zebs.ch] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.bak
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:02:56
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:02:48.367250 2026] [security2:error] [pid 5794:tid 5794] [client 162.241.63.11:23328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailinghonu.com"] [uri "/wp-config.php.bak"] [unique_id "arKYmD2YMg6hELqRIaGKyQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:47:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:47:27.555212 2026] [security2:error] [pid 5238:tid 5238] [client 162.241.63.11:17540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hatebay.com"] [uri "/wp-config.php.bak"] [unique_id "arJqzztZF-pCFe8yZnxPZgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:49:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 162.241.63.11 (sh-pro94.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:49:01.700092 2026] [security2:error] [pid 24950:tid 24950] [client 162.241.63.11:19448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rentstrippersindio.com"] [uri "/wp-config.php.bak"] [unique_id "arJA_eBYyHm-Wt9a-LQZsgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2024-02-26 03:49:44
(2 years ago)
Web attack from 162.241.63.11
Web App Attack
๐บ๐ธ
mnsf
2024-02-25 21:03:12
(2 years ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2024-02-25 01:26:03
(2 years ago)
Looking for CMS/PHP/SQL vulnerablilities - 1
Exploited Host
Web App Attack