🇺🇸
TPI-Abuse
2026-09-08 06:50:56
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:50:52.039010 2026] [security2:error] [pid 1714858:tid 1715282] [client 164.132.224.213:58730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "visionforandfromchildren.org"] [uri "/wp-config.php~"] [unique_id "ap-wTH0bCZPretB_348CogAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
burlacu.org
2026-09-08 05:51:03
(13 hours ago)
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 19 attempt ...
show more
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 19 attempts. Blocked automatically.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-08 05:49:29
(13 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:16:12
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:16:04.881084 2026] [security2:error] [pid 21692:tid 21692] [client 164.132.224.213:47292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prostar.industries"] [uri "/wp-config.php.save"] [unique_id "ap-aFPWdZ1tu3rAuJkYcJgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-08 04:33:08
(14 hours ago)
Many_bad_calls
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:00:56
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:00:52.416343 2026] [security2:error] [pid 9698:tid 9698] [client 164.132.224.213:48274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.kbalan.com"] [uri "/wp-config.php.save"] [unique_id "ap-IdF77d_WLUKxmz-Ca4AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:32:04
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:31:57.411075 2026] [security2:error] [pid 10356:tid 10356] [client 164.132.224.213:47992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ink2wear.com"] [uri "/wp-config.php.bak"] [unique_id "ap9znTd6guJY1WAOTzWC1AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:13:47
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:13:43.916218 2026] [security2:error] [pid 29469:tid 29469] [client 164.132.224.213:49654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pleaseaddbacon.com"] [uri "/wp-config.php~"] [unique_id "ap9vVxnOAEJIKhB3sBUvjgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Rip
2026-09-08 01:17:54
(17 hours ago)
Restricted File Access Attempts
Port Scan
Web App Attack
🇲🇾
Rizzy
2026-09-08 00:43:18
(18 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TAY
2026-09-07 22:46:13
(20 hours ago)
164.132.224.213 - - [08/Sep/2026:06:45:59 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 56031 "-" "Mo ...
show more
164.132.224.213 - - [08/Sep/2026:06:45:59 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 56031 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
164.132.224.213 - - [08/Sep/2026:06:46:00 +0800] "GET /wp-config.php~ HTTP/1.1" 404 56009 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
164.132.224.213 - - [08/Sep/2026:06:46:02 +0800] "GET /wp-config.php.save HTTP/1.1" 404 56009 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
164.132.224.213 - - [08/Sep/2026:06:46:08 +0800] "GET /wp-config.php.old HTTP/1.1" 404 56031 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
164.132.224.213 - - [08/Sep/2026:06:46:10 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 56031 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 21:37:44
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:37:37.157937 2026] [security2:error] [pid 32523:tid 32523] [client 164.132.224.213:48518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usaenquirer.com"] [uri "/wp-config.php~"] [unique_id "ap8uocDlKT5XusdGeI-0lQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 21:10:05
(21 hours ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:48:20
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 164.132.224.213 (vps-c1adef4c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:48:14.032145 2026] [security2:error] [pid 17954:tid 17954] [client 164.132.224.213:37886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tttns.com"] [uri "/about-jason//wp-config.php.save"] [unique_id "ap8jDplF2HPttcPbRz9mAAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 19:24:11
(23 hours ago)
Aggressive web search of vulnerable pages: /.env /phpinfo.php /info.php /test.php /backup.sql /backu ...
show more
Aggressive web search of vulnerable pages: /.env /phpinfo.php /info.php /test.php /backup.sql /backup.sql.gz /backup.zip ...
show less
Web App Attack