๐ฉ๐ช
Jochen Pretli
2026-09-16 10:10:21
(6 days ago)
connection to honeypot
Email Spam
Port Scan
๐ฉ๐ช
Jochen Pretli
2026-09-14 22:46:54
(1 week ago)
connection to honeypot
Email Spam
Port Scan
๐ฒ๐ฝ
octageeks.com
2026-09-13 04:24:18
(1 week ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 23:47:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:47:49.852751 2026] [security2:error] [pid 17317:tid 17317] [client 165.227.132.191:52260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grannyswash.kunzteam.com"] [uri "/.git/index"] [unique_id "aqXkpdp7zmhnZ7uyJfNKiQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 23:32:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:32:21.885636 2026] [security2:error] [pid 22407:tid 22407] [client 165.227.132.191:39232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.casadelsolmexico.net"] [uri "/.env.txt"] [unique_id "aqXhBbOUbpbc5DFD00IowgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 19:32:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 15:32:15.327790 2026] [security2:error] [pid 23231:tid 23231] [client 165.227.132.191:54120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rachelfia.fiasdesigns.com"] [uri "/wp-config.php.save"] [unique_id "aqWovzI1I5d9BJJGebqMdAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 17:46:15
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 13:46:10.185266 2026] [security2:error] [pid 31235:tid 31235] [client 165.227.132.191:57634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hayrun.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hayrun.com"] [uri "/dump.sql"] [unique_id "aqWP4gHsMl6sa-KhY2VYTwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-12 15:00:05
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 13:23:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:23:16.583568 2026] [security2:error] [pid 26220:tid 26220] [client 165.227.132.191:55568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ink2wear.com"] [uri "/wp-config.php.orig"] [unique_id "aqVSRM_sQ80V1-GsOjFAjAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 12:37:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:37:50.475672 2026] [security2:error] [pid 24766:tid 24766] [client 165.227.132.191:42654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kbalan.com"] [uri "/wp-config.php.bak"] [unique_id "aqVHno1rYvawV0pcUMiVlgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 10:47:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:47:04.907836 2026] [security2:error] [pid 16959:tid 16959] [client 165.227.132.191:42820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldsite.soudertonbigred.org"] [uri "/wp-config.php.old"] [unique_id "aqUtqBKmvlQQZj6AigJrxwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 09:25:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 165.227.132.191 (app.theofficebelgrade.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:25:16.424556 2026] [security2:error] [pid 23941:tid 24030] [client 165.227.132.191:55858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iamfluff.com"] [uri "/wp-config.php.swp"] [unique_id "aqUafGmozhmNSp9dTcD1YwAAAcM"]
show less
Brute-Force
Bad Web Bot
Web App Attack