πΊπΈ
TPI-Abuse
2026-09-14 12:43:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.187.208 (vmi3512806.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.187.208 (vmi3512806.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 08:43:15.599367 2026] [security2:error] [pid 19179:tid 19179] [client 169.58.187.208:58696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prostar.industries"] [uri "/wp-config.php.old"] [unique_id "aqfr4_dhPXan-mVvmgJmgAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-14 06:29:05
(2 days ago)
Probing websites for vulnerabilities
Web App Attack
π³π±
Alt255
2026-09-14 06:15:08
(2 days ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 169 ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 169.58.187.208 - - \[14/Sep/2026:08:15:07 +0200\] "GET /wp-config.php.save HTTP/1.1" 301 5879 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 06:14:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.187.208 (vmi3512806.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.187.208 (vmi3512806.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:14:02.803088 2026] [security2:error] [pid 10590:tid 10590] [client 169.58.187.208:48194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adlc18.org"] [uri "/wp-config.php~"] [unique_id "aqeQqtiiYLeGUmqoR4XeugAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 05:40:04
(2 days ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.save HTTP/1.1
Hacking
Web App Attack
π©πͺ
IVski.com
2026-09-14 04:11:14
(2 days ago)
IVski WAF | Metabase CVE-2026-72898 probe - querying /api/session/properties
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-14 03:55:19
(2 days ago)
Repeated inbound connection attempts blocked by firewall. Observed at least twice within 24 hours.
Hacking
Anonymous
2026-09-14 02:15:02
(3 days ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-09-14 00:28:39
(3 days ago)
Blocked by firewall on hugin [3000/tcp] | Rule: UFW | SPT: 41350 | TTL: 58 | LEN: 60 | TOS: 0x00 β’ R ...
show more
Blocked by firewall on hugin [3000/tcp] | Rule: UFW | SPT: 41350 | TTL: 58 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπ¦
URAN Publishing Service
2026-09-13 18:55:27
(3 days ago)
[13/Sep/2026:21:55:27 +0300] -- 169.58.187.208 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[13/Sep/2026:21:55:27 +0300] -- 169.58.187.208 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1
show less
Bad Web Bot
Web App Attack
π«π·
COMAITE
2026-09-13 17:05:19
(3 days ago)
Suspicious URL access.
Web App Attack
π©πͺ
LRob
2026-09-13 15:53:03
(3 days ago)
Walking a list of paths that do not exist (scanning) | method: GET | path: /api/session/properties | ...
show more
Walking a list of paths that do not exist (scanning) | method: GET | path: /api/session/properties | 2026-09-13 15:53 UTC
show less
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-13 14:36:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.187.208 (vmi3512806.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.187.208 (vmi3512806.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:36:05.199457 2026] [security2:error] [pid 28396:tid 28396] [client 169.58.187.208:37566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usaenquirer.com"] [uri "/wp-config.php.bak"] [unique_id "aqa01VuiXcsETGEoc0OBWwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
taivas.nl
2026-09-13 04:32:46
(3 days ago)
Many_bad_calls
Web App Attack
πΈπͺ
SkyDancer
2026-09-13 00:56:55
(4 days ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH