๐บ๐ธ
lavnet.net
2026-09-17 02:41:59
(1 day ago)
[Thu Sep 17 02:41:58.561458 2026] [authz_core:error] [pid 1476873:tid 1476962] [client 169.58.192.18 ...
show more
[Thu Sep 17 02:41:58.561458 2026] [authz_core:error] [pid 1476873:tid 1476962] [client 169.58.192.180:47858] AH01630: client denied by server configuration: /var/www/thejunkymonkey.com/web/index.php
[Thu Sep 17 02:41:58.561728 2026] [authz_core:error] [pid 1476873:tid 1476962] [client 169.58.192.180:47858] AH01630: client denied by server configuration: /var/www/thejunkymonkey.com/web/index.php
[Thu Sep 17 02:41:58.916851 2026] [authz_core:error] [pid 1476875:tid 1476905] [client 169.58.192.180:46408] AH01630: client denied by server configuration: /var/www/thejunkymonkey.com/web/index.php
...
show less
Brute-Force
๐ฟ๐ฆ
conure.sh
2026-09-15 10:17:48
(3 days ago)
csagent: score 16.0: wp-config backup grab x2; 1 domain(s) in 1m28s
Web App Attack
๐ซ๐ท
masterguru
2026-09-15 07:29:56
(3 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 169.58.192.180 (DE/Germany/vmi3514955 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 169.58.192.180 (DE/Germany/vmi3514955.contaboserver.net): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ง๐ช
taivas.nl
2026-09-15 04:32:31
(3 days ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 17:14:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.192.180 (vmi3514955.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.192.180 (vmi3514955.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 13:14:21.598741 2026] [security2:error] [pid 26468:tid 26468] [client 169.58.192.180:48316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.doreenkimura.com.misscharlottemusic.com"] [uri "/wp-config.php~"] [unique_id "aqgrbajZaBxSCjaY8U-sMQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-14 16:47:41
(4 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 169.58.192.180 (DE/Germany/vmi3514955 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 169.58.192.180 (DE/Germany/vmi3514955.contaboserver.net): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ณ๐ฑ
i-turnradio.nl
2026-09-14 16:21:54
(4 days ago)
2026-09-14 @ 18:21:34 (CET) ~ Blocked for trying to access: /api/session/properties
Web App Attack
๐ง๐ช
taivas.nl
2026-09-14 16:02:12
(4 days ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-14 15:33:55
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.192.180 (vmi3514955.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.192.180 (vmi3514955.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 11:33:48.008913 2026] [security2:error] [pid 20576:tid 20576] [client 169.58.192.180:45732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "activethinkers.net"] [uri "/wp-config.php.bak"] [unique_id "aqgT3FwYohC1yduVowe2EwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-14 10:41:43
(4 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /index.php | 2026-09-14 10:41 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-14 07:46:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.192.180 (vmi3514955.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.192.180 (vmi3514955.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 03:46:15.287765 2026] [security2:error] [pid 4078632:tid 4078653] [client 169.58.192.180:53404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rubenluis.com"] [uri "/wp-config.php.save"] [unique_id "aqemR3DUL3zvi9F4j178SwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 06:36:45
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.192.180 (vmi3514955.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.192.180 (vmi3514955.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:36:40.560404 2026] [security2:error] [pid 10731:tid 10731] [client 169.58.192.180:45292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehealthyplaceclayton.com"] [uri "/wp-config.php.bak"] [unique_id "aqeV-OF2w-IBsUSYYVGWmAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-14 05:57:33
(4 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-14 03:46:38
(4 days ago)
Web application attack detected.
Web App Attack
๐ง๐ช
cmbplf
2026-09-14 03:33:10
(4 days ago)
119 requests with url.path *.php.bak
Brute-Force
Bad Web Bot