🇵🇱
gandaflux
2026-09-15 14:52:23
(11 minutes ago)
185.104.44.182 [redacted-domain] - [15/Sep/2026:16:52:22 +0200] "GET /wp-config.php.bak HTTP/1.1" 40 ...
show more
185.104.44.182 [redacted-domain] - [15/Sep/2026:16:52:22 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.104.44.182 [redacted-domain] - [15/Sep/2026:16:52:22 +0200] "GET /wp-config.php~ HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.104.44.182 [redacted-domain] - [15/Sep/2026:16:52:22 +0200] "GET /wp-config.php.save HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:52:12
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (business-112.default-host.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:52:08.728176 2026] [security2:error] [pid 28451:tid 28451] [client 185.104.44.182:24404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puckerbuttbikinis.com"] [uri "/wp-config.php~"] [unique_id "aqlbmLGv9iXe-r5fQ8PoTAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-15 14:41:13
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (UA/Ukraine/business-112.default ...
show more
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (UA/Ukraine/business-112.default-host.net): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-15 14:37:41
(26 minutes ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:31:06
(32 minutes ago)
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (business-112.default-host.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:31:01.973372 2026] [security2:error] [pid 10193:tid 10193] [client 185.104.44.182:55736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.crep-psych.org"] [uri "/wp-config.php.old"] [unique_id "aqlWperne6ra6GhlEZYmQAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-15 14:28:08
(35 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-15 14:08:58
(55 minutes ago)
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (business-112.default-host.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:08:55.252760 2026] [security2:error] [pid 1064061:tid 1064061] [client 185.104.44.182:55770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troop9weymouth.com"] [uri "/wp-config.php.txt"] [unique_id "aqlRd0TXt4pKLapzHTBWHwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-15 13:58:58
(1 hour ago)
185.104.44.182 - - [15/Sep/2026:21:58:53 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 486 "-" "Mozil ...
show more
185.104.44.182 - - [15/Sep/2026:21:58:53 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 486 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.104.44.182 - - [15/Sep/2026:21:58:53 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 54906 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.104.44.182 - - [15/Sep/2026:21:58:55 +0800] "GET /wp-config.php~ HTTP/1.1" 301 480 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.104.44.182 - - [15/Sep/2026:21:58:55 +0800] "GET /wp-config.php~ HTTP/1.1" 404 54881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.104.44.182 - - [15/Sep/2026:21:58:57 +0800] "GET /wp-config.php.save HTTP/1.1" 301 488 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
...
show less
Brute-Force
🇺🇸
VanKoh
2026-09-15 13:50:17
(1 hour ago)
185.104.44.182 - - [15/Sep/2026:07:50:14 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Mozilla ...
show more
185.104.44.182 - - [15/Sep/2026:07:50:14 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.104.44.182 - - [15/Sep/2026:07:50:14 -0600] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.104.44.182 - - [15/Sep/2026:07:50:16 -0600] "GET /wp-config.php.save HTTP/1.1" 404 58296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web App Attack
🇳🇱
Savvii
2026-09-15 13:42:33
(1 hour ago)
20 attempts against mh-misbehave-ban on bud
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-15 13:29:37
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Alt255
2026-09-15 13:23:20
(1 hour ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 185.104.44.182 - - [15/Sep/2026:15:23:06 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 58811 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
Lennart Kramer
2026-09-15 11:46:45
(3 hours ago)
Restricted File Access Attempt | Matched phrase "*wp-json*" at /wp-json/gravitysmtp/v1/tests/mock-da ...
show more
Restricted File Access Attempt | Matched phrase "*wp-json*" at /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 11:14:51
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (business-112.default-host.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.104.44.182 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:14:46.876527 2026] [security2:error] [pid 1237:tid 1237] [client 185.104.44.182:25034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.godcanuseyou.com"] [uri "/wp-config.php.old"] [unique_id "aqkopoA62TFfSynWFpeygAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-15 10:56:48
(4 hours ago)
csagent: score 20.4: wp-config backup grab x2, 404 noise floor x2; 1 domain(s) in 2s
Web App Attack