Anonymous
2026-09-16 13:18:22
(1 hour ago)
CPOWCO WEBEXPLOIT 179.198.201.82 (srv1952707.hstgr.cloud)
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-16 11:50:55
(3 hours ago)
csagent: score 25.0: wp-config backup grab x3, 404 noise floor x3; 2 domain(s) in 0s
Web App Attack
๐บ๐ธ
cwytech
2026-09-16 01:28:56
(13 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:21:19
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:21:13.322288 2026] [security2:error] [pid 30992:tid 30992] [client 179.198.201.82:53506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danielbrower.com"] [uri "/wp-config.php~"] [unique_id "aqnvCecpsTDciufP0u0WZQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-15 21:14:55
(18 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ Directory Listings (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:07:12
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:07:08.401082 2026] [security2:error] [pid 10004:tid 10023] [client 179.198.201.82:55596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativedemocrat.com"] [uri "/wp-config.php.orig"] [unique_id "aqmlbDK_RXebi7Lrqk8u-wAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:29:10
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:29:06.127032 2026] [security2:error] [pid 2455:tid 2455] [client 179.198.201.82:37250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kmp.net"] [uri "/.env.txt"] [unique_id "aqmOcjAt2IFQuFXRz9lM3AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 09:11:18
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-15 07:27:12
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 05:54:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:54:51.168186 2026] [security2:error] [pid 31593:tid 31593] [client 179.198.201.82:39026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artizandecor.com"] [uri "/.git/config"] [unique_id "aqjdq2RXaLihkEV6JVwwYQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 01:23:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:23:25.964385 2026] [security2:error] [pid 17658:tid 17658] [client 179.198.201.82:48472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sharawi-gum.com"] [uri "/wp-config.php.bak"] [unique_id "aqieDVZMduw73BnN0_viCgAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 23:41:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:40:59.979902 2026] [security2:error] [pid 30022:tid 30022] [client 179.198.201.82:35980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianwhitty.com"] [uri "/wp-config.php.orig"] [unique_id "aqiGC6KJw8pa7OEP7wv8ugAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
foxxelabs
2026-09-14 17:28:26
(1 day ago)
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: anseo | Reason(s): Known exp ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: anseo | Reason(s): Known exploit path: /.env | User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Sa
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 16:59:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 179.198.201.82 (srv1952707.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 12:59:08.620788 2026] [security2:error] [pid 13157:tid 13157] [client 179.198.201.82:44102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anniesherbals.com"] [uri "/.env.txt"] [unique_id "aqgn3Nl2EnKURwabvds42QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rip
2026-09-14 08:15:35
(2 days ago)
WordPress fingerprinting and attack surface probing
Port Scan
Web App Attack