🇺🇸
TPI-Abuse
2026-09-06 13:06:06
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:06:01.821515 2026] [security2:error] [pid 189319:tid 189319] [client 185.208.164.72:32842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotelausland.com"] [uri "/wp-config.php.save"] [unique_id "ap1lOYrzk5awJV5VMQ7brAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 07:52:13
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇬🇧
Apache
2026-09-06 07:12:26
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (PL/Poland/s72.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (PL/Poland/s72.cyber-folks.pl): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:21:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:21:11.720256 2026] [security2:error] [pid 15650:tid 15650] [client 185.208.164.72:36126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.femalegamblers.org"] [uri "/wp-config.php.save"] [unique_id "apzqN2WUGvAYDHI1gUwY1AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:20:45
(5 days ago)
SPARSDE WEBEXPLOIT 185.208.164.72 (s72.cyber-folks.pl)
Web App Attack
🇳🇱
maxxsense
2026-09-06 00:44:04
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 185.208.164.72 (PL/Poland/s72.cyber-fol ...
show more
(mod_security) mod_security triggered on hostname [redacted] 185.208.164.72 (PL/Poland/s72.cyber-folks.pl)
show less
SQL Injection
🇫🇷
Octopuce
2026-09-06 00:07:42
(5 days ago)
Aggressive web search of vulnerable pages: /.env /phpinfo.php /info.php /test.php /backup.sql /backu ...
show more
Aggressive web search of vulnerable pages: /.env /phpinfo.php /info.php /test.php /backup.sql /backup.sql.gz /backup.zip ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 19:57:41
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:57:36.604735 2026] [security2:error] [pid 26379:tid 26379] [client 185.208.164.72:37802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.earthwormensemble.doublenaughtspycar.com"] [uri "/wp-config.php~"] [unique_id "apx0MLR1OaMCpDcKLvlV4gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-05 16:06:04
(6 days ago)
185.208.164.72 - - [06/Sep/2026:00:05:58 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6135 "-" "Mozi ...
show more
185.208.164.72 - - [06/Sep/2026:00:05:58 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6135 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.208.164.72 - - [06/Sep/2026:00:06:00 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 46587 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.208.164.72 - - [06/Sep/2026:00:06:01 +0800] "GET /wp-config.php~ HTTP/1.1" 301 6132 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.208.164.72 - - [06/Sep/2026:00:06:02 +0800] "GET /wp-config.php~ HTTP/1.1" 404 46587 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
185.208.164.72 - - [06/Sep/2026:00:06:03 +0800] "GET /wp-config.php.save HTTP/1.1" 301 6136 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, li
...
show less
Brute-Force
Anonymous
2026-09-05 07:34:46
(6 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 07:14:40
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 03:14:34.848602 2026] [security2:error] [pid 18169:tid 18169] [client 185.208.164.72:45330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thereisaplaceonearth.com"] [uri "/wp-config.php.txt"] [unique_id "apvBWhimNMeRcFeWIAJaAwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 00:31:29
(6 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 23:50:01
(6 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 23:07:17
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 19:07:12.730663 2026] [security2:error] [pid 27725:tid 27725] [client 185.208.164.72:32824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ablogisticsgroup.com"] [uri "/wp-config.php.bak"] [unique_id "aptPILyZUlE3ZPQtuR9d0gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:13:35
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 185.208.164.72 (s72.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:13:30.811654 2026] [security2:error] [pid 8732:tid 8732] [client 185.208.164.72:40172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gerrytolentino.praemiumtech.com"] [uri "/wp-config.php.swp"] [unique_id "aptCip5VENiYUMekReARzAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack