🇬🇧
consul.to
2026-09-05 17:18:03
(53 minutes ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 14:28:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 10:28:39.465690 2026] [security2:error] [pid 3050:tid 3050] [client 172.232.240.54:52676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjtent.com"] [uri "/wp-config.php"] [unique_id "apwnF-rv3lH-Pzm9TKYguwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
rdpguard.com
2026-09-05 13:41:09
(4 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
🇺🇸
Penny Packer
2026-09-05 12:57:07
(5 hours ago)
Fail2Ban apache-404
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 11:58:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 07:58:40.204252 2026] [security2:error] [pid 3553:tid 3568] [client 172.232.240.54:52640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aeaus.com"] [uri "/wp-config.php"] [unique_id "apwD8EEi-jtR2t4gjyVv4wAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-05 11:52:15
(6 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /1.php | ua: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36 | 2026-09-05 11:52 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 10:39:50
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 06:39:46.987408 2026] [security2:error] [pid 7416:tid 7416] [client 172.232.240.54:59691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thevenicecafe.com"] [uri "/wp-config.php"] [unique_id "apvxchyDNhp2Zj3h1TnyMwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 06:18:33
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-05 05:39:41
(12 hours ago)
[ns41.kdns.gr] httpd-shell-path-probe: sites=www.monastiria.gr; logs=/var/log/httpd/domains/monastir ...
show more
[ns41.kdns.gr] httpd-shell-path-probe: sites=www.monastiria.gr; logs=/var/log/httpd/domains/monastiria.gr.log; samples=/0byte.php | /alfa.php | /byp.php
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 03:01:43
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 23:01:38.370928 2026] [security2:error] [pid 31238:tid 31238] [client 172.232.240.54:53043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "truecontrarian.com"] [uri "/wp-config.php"] [unique_id "apuGEoyYbQoWjo8u3A6rTAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 22:54:15
(19 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇦🇹
penguin-solutions.at
2026-09-04 20:32:54
(21 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇳🇿
Antinson
2026-09-04 17:52:44
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇫🇷
dynamix
2026-09-04 16:53:04
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:48:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 172.232.240.54 (172-232-240-54.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:48:43.539559 2026] [security2:error] [pid 9368:tid 9368] [client 172.232.240.54:60859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "box903.com"] [uri "/wp-config.php"] [unique_id "apr2a2o_wL4XFlJbVEhr-QAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack