๐บ๐ธ
TPI-Abuse
2026-06-19 08:10:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 04:10:02.455490 2026] [security2:error] [pid 7368:tid 7368] [client 172.68.183.72:10148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackstarmgmt.com"] [uri "/.git/HEAD"] [unique_id "ajT5Wg1HgzKE_WbimtQU2AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
srtzero
2026-06-15 23:25:21
(1 week ago)
172.68.183.72 - - [16/Jun/2026:01:25:20 +0200] "GET /wp-admin/install.php?step=1 HTTP/2.0" 404 162 " ...
show more
172.68.183.72 - - [16/Jun/2026:01:25:20 +0200] "GET /wp-admin/install.php?step=1 HTTP/2.0" 404 162 "-" "http://convergencegaming.net/wp-admin/install.php?step=1"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 08:44:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 04:44:01.875255 2026] [security2:error] [pid 26561:tid 26561] [client 172.68.183.72:10681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pearson-specter.com.iacarbonell.com"] [uri "/.git/config"] [unique_id "ai5p0ckPn2c8hqnhlhwegQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 06:04:57
(2 weeks ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/install.php
Web App Attack
๐ท๐บ
DZBOT
2026-06-10 04:25:03
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ง๐ท
chronos
2026-05-28 00:15:51
(1 month ago)
2026-05-27 20:25:05 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-23 17:40:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 13:40:24.351352 2026] [security2:error] [pid 30492:tid 30492] [client 172.68.183.72:12132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skipspsaexchange.com"] [uri "/.git/config"] [unique_id "ahHmiMf7DIzQcLFvRnMB_wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 14:21:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 10:20:59.892561 2026] [security2:error] [pid 19614:tid 19614] [client 172.68.183.72:9864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "justinrudd.com"] [uri "/.git/config"] [unique_id "agnOy0l6Yg58SDTjrqvFbAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 13:59:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.183.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 09:59:34.264158 2026] [security2:error] [pid 11928:tid 11928] [client 172.68.183.72:10697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "limegreenvinyl.com"] [uri "/.git/config"] [unique_id "agnJxtAgak9CvynMkCU-AAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-05-15 06:03:43
(1 month ago)
Automated WordPress exploit probe caught via honeydomain infrastructure. Bot used http://dispensight ...
show more
Automated WordPress exploit probe caught via honeydomain infrastructure. Bot used http://dispensight.help/wp-admin/install.php?step=1 as User-Agent. Honeydomain operator-controlled bait; confirmed malicious WordPress scanner. Cloudflare Sweden proxy.
show less
Bad Web Bot
๐ฉ๐ช
F242
2026-05-14 14:58:38
(1 month ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
xxkodedxx
2026-05-13 06:31:50
(1 month ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: SE / AS13335 Cloudflare, Inc.
Active: 06:30:52 UTC
Volume: 1 HTTP req
Probed: /wp-admin/install.php?step=1
Status mix: 444ร1
UA: "http://zvxlabs.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-05-04 07:19:50
(1 month ago)
wordpress scan on 860.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-04-20 02:05:59
(2 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
mawan
2026-04-18 02:02:45
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack