🇺🇸
TPI-Abuse
2026-09-14 06:44:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:44:15.191221 2026] [security2:error] [pid 15403:tid 15431] [client 185.231.182.97:57414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reghay.com"] [uri "/wp-config.php.bak"] [unique_id "aqeXvwqULHpyyOf1w1fTkAAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-14 06:00:01
(3 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-14 05:42:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 01:42:30.368818 2026] [security2:error] [pid 31780:tid 31780] [client 185.231.182.97:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pulleasy.com"] [uri "/.env.bak"] [unique_id "aqeJRrQh3IoOhW20uqE6pQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-14 04:33:13
(4 hours ago)
Many_bad_calls
Web App Attack
🇸🇪
vaia.cloud
2026-09-14 03:15:03
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇲🇾
Rizzy
2026-09-13 23:35:41
(9 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-13 23:10:04
(10 hours ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 22:21:44
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:21:37.662396 2026] [security2:error] [pid 26639:tid 26639] [client 185.231.182.97:32850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenewplantation.org"] [uri "/wp-config.php.bak"] [unique_id "aqch8XUYZXIuEDGzAqbySwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 21:59:16
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:59:08.011322 2026] [security2:error] [pid 3217:tid 3217] [client 185.231.182.97:50606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgtek.com"] [uri "/wp-config.php.bak"] [unique_id "aqccrM8vCnzyKB6oku35GAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-13 21:52:00
(11 hours ago)
[14/Sep/2026:00:52:00 +0300] -- 185.231.182.97 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[14/Sep/2026:00:52:00 +0300] -- 185.231.182.97 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 21:01:58
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:01:52.317762 2026] [security2:error] [pid 1669132:tid 1669132] [client 185.231.182.97:39608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joeordie.com"] [uri "/wp-config.php~"] [unique_id "aqcPQBskIjlFzypvdZ_EBgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-13 19:02:12
(14 hours ago)
Site scraper
Web App Attack
🇧🇪
taivas.nl
2026-09-13 18:32:11
(14 hours ago)
Bad_requests
Bad Web Bot
🇺🇸
kosada.com
2026-09-13 15:36:15
(17 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /api/session/reset_password (HTTP/1. ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /api/session/reset_password (HTTP/1.1 port 80, bogus vhost, user agent: "metabase-cve-2026-72898-detect/1.0 (benign detection probes only)")
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 14:18:22
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.231.182.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:18:16.674694 2026] [security2:error] [pid 1113:tid 1113] [client 185.231.182.97:37278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hayrun.com"] [uri "/wp-config.php~"] [unique_id "aqawqAYPU8K-kouAkePDhgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack