๐ฉ๐ช
Phenix Info
2026-09-24 06:44:54
(15 hours ago)
SmallGuard.fr - Empty User Agent
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 23:08:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:08:10.808035 2026] [security2:error] [pid 1462295:tid 1462295] [client 178.254.15.200:34928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sketchnotebook.com"] [uri "/wp-config.php.bak"] [unique_id "arMKWoULwlIR7mItY6a2OQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:17:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:17:25.598418 2026] [security2:error] [pid 18108:tid 18108] [client 178.254.15.200:41186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lekacos.com"] [uri "/wp-config.php.bak"] [unique_id "arLiVb0MI2xh0pZ0QD26UwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:46:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:46:12.770491 2026] [security2:error] [pid 28120:tid 28120] [client 178.254.15.200:50802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "communitycontrol.com"] [uri "/wp-config.php.bak"] [unique_id "arLM9Pu_IwXqTLM8JaIg1gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:28:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:28:15.156833 2026] [security2:error] [pid 3283:tid 3283] [client 178.254.15.200:35214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buffaloweddingreception.com"] [uri "/wp-config.php.bak"] [unique_id "arK6r-Ym6It0nPo1iFwrsQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:07:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:07:22.777482 2026] [security2:error] [pid 32597:tid 32597] [client 178.254.15.200:60474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arriagarealestate.com"] [uri "/wp-config.php.bak"] [unique_id "arKnuqzxBjV5C-TCv7ducwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 14:59:10
(2 days ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 178.254.15.200 - - [22/Sep/2026:16:59:03 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 471 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:56:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:56:02.454515 2026] [security2:error] [pid 20817:tid 20817] [client 178.254.15.200:42680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mahoninginn.com"] [uri "/wp-config.php.bak"] [unique_id "arKI8iHNaHNFXpOcinjPhAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-22 12:35:39
(2 days ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:58:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:58:07.060701 2026] [security2:error] [pid 8461:tid 8461] [client 178.254.15.200:34104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kletzer.com"] [uri "/wp-config.php.bak"] [unique_id "arJtTzYQk0WPodomiHydPQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:06:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:06:39.396011 2026] [security2:error] [pid 31640:tid 31676] [client 178.254.15.200:53670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sonatro.io"] [uri "/wp-config.php.bak"] [unique_id "arJFH2eSS3Ir5GD3d884vAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:46:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 178.254.15.200 (sh-73.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:46:28.769224 2026] [security2:error] [pid 14030:tid 14030] [client 178.254.15.200:49334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "independentmusicconference.com"] [uri "/wp-config.php.bak"] [unique_id "arJAZCoTzhqimVmrPr3lAQAAAGw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 19:52:44
(3 days ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: /seed.txt | 2026-09-21 19:52 UTC
show less
Bad Web Bot
Anonymous
2025-07-07 23:31:02
(1 year ago)
Bot / scanning and/or hacking attempts: GET /wp-config HTTP/1.1, GET /wp-config.php.old HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config HTTP/1.1, GET /wp-config.php.old HTTP/1.1, GET /wp-config.php.save HTTP/1.1, GET /wp-config.php.orig HTTP/1.1
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2025-07-06 14:00:06
(1 year ago)
Detected attack by Imunify360
Brute-Force
Web App Attack