Anonymous
2026-10-06 09:41:19
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-10-06 07:03:03
(1 day ago)
block ruleset 39D9DF3582BC0B50B0A9559A2D05D44391E672DC
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 03:52:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your- ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:52:10.414149 2026] [security2:error] [pid 17060:tid 17060] [client 176.9.38.169:37122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wetlizarddiveteam.com"] [uri "/wp-config.php_"] [unique_id "asRwaoYlMWceuMn7bWzkcwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-05 09:26:54
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
FD-IX
2026-10-05 00:23:31
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-03 23:25:31
(3 days ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 176.9.38.169 - - [04/Oct/2026:01:25:20 +0200] "GET /.wp-config.bak HTTP/1.1" 301 491 "-" "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; EIE10;ENUSMSN; rv:11.0) like Gecko"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-03 14:09:00
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 176.9.38.169 (DE/Germany/static.169.38.9.176.cl ...
show more
(mod_security) mod_security (id:949110) triggered by 176.9.38.169 (DE/Germany/static.169.38.9.176.clients.your-server.de): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 03:10:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your- ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:10:49.827285 2026] [security2:error] [pid 27963:tid 27963] [client 176.9.38.169:47680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whlr.net"] [uri "/wp-config.php_"] [unique_id "ar8guY8O5FvoU8Ga5ng42gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-02 02:39:23
(5 days ago)
Cloudflare WAF: Request Path: /sftp-config.json Request Query: Host: whk.elhacker.net userAgent: Mo ...
show more
Cloudflare WAF: Request Path: /sftp-config.json Request Query: Host: whk.elhacker.net userAgent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0 Action: block Source: firewallManaged ASN Description: Hetzner Online GmbH Country: DE Method: GET Timestamp: 2026-10-02T02:39:23Z ruleId: c2a2f414a67c409f90cccb6c5bba0215. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:26:50
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your- ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:26:42.149748 2026] [security2:error] [pid 12714:tid 12714] [client 176.9.38.169:57048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wilklass.com"] [uri "/wp-config.php_"] [unique_id "ar0cImHFedZjZULswhS9KgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-09-30 06:13:56
(1 week ago)
2026-09-30 @ 08:13:39 (CET) ~ Blocked for trying to access: /_wpeprivate/config.json
Web App Attack
Anonymous
2026-09-30 04:58:44
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:53:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your- ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:53:50.813577 2026] [security2:error] [pid 9848:tid 9848] [client 176.9.38.169:52410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildpete.com"] [uri "/wp-config.php_"] [unique_id "aryV3tAqQEkVw4CWpGkzxgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:05:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your- ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.38.169 (static.169.38.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:05:38.791047 2026] [security2:error] [pid 27006:tid 27006] [client 176.9.38.169:42810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildcomaui.com"] [uri "/wp-config.php_"] [unique_id "arwoIrms0fCe3EqVNA6eVAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
www.winos.me
2026-09-29 11:37:24
(1 week ago)
Scanning for sensitive files/paths: /wp-config.
Hacking
Web App Attack