🇺🇸
TPI-Abuse
2026-09-05 09:08:20
(6 minutes ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 05:08:16.651658 2026] [security2:error] [pid 23073:tid 23073] [client 185.46.151.62:58724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kbalan.com"] [uri "/wp-config.php.swp"] [unique_id "apvcAJgmNgwVmYCFGtOlVwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-05 08:32:11
(42 minutes ago)
Bad_requests
Bad Web Bot
🇨🇦
design2web.ca
2026-09-05 08:22:33
(52 minutes ago)
[UniFi FW] Web application attack on port 80 (HTTP) | Policy: Region Blocking | Proto: TCP | Src: 18 ...
show more
[UniFi FW] Web application attack on port 80 (HTTP) | Policy: Region Blocking | Proto: TCP | Src: 185.46.151.62:53406 | SrcRegion: UA | Svc: HTTP | Detected: 2026-09-05 07:45:47 UTC | ISP: "GIGATRANS UKRAINE", LLC | D2W UniFi AbuseIPDB Reporter v2
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-05 08:21:28
(53 minutes ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 04:21:21.404033 2026] [security2:error] [pid 9044:tid 9044] [client 185.46.151.62:48588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sharawi-gum.com"] [uri "/wp-config.php.bak"] [unique_id "apvRAXwoROkchOz0C8AgtwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 06:35:56
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 02:35:52.546766 2026] [security2:error] [pid 22459:tid 22459] [client 185.46.151.62:54274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthtwoworkshop.com"] [uri "/wp-config.php.swp"] [unique_id "apu4SIUyCL18H1KjW_lsXQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 03:15:09
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 23:15:00.675725 2026] [security2:error] [pid 16883:tid 16883] [client 185.46.151.62:40028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonegym.com"] [uri "/wp-config.php.bak"] [unique_id "apuJNJAcNwwL4bWYQyLGtAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 01:32:09
(7 hours ago)
[PathScanning] Path scanning/probing detected: Backup file probe; Sensitive file access: environment ...
show more
[PathScanning] Path scanning/probing detected: Backup file probe; Sensitive file access: environment file (path: /.env.bak) | [ConfigAccess] Configuration file access attempt: Config file access attempt: .env; Environment configuration file (path: /.env.bak)
show less
Port Scan
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 00:59:38
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:59:34.186741 2026] [security2:error] [pid 28580:tid 28580] [client 185.46.151.62:57744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bikinitweets.com"] [uri "/wp-config.php.swp"] [unique_id "aptpdqQxyOkQsoArL9eSJgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 00:40:46
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:40:39.261131 2026] [security2:error] [pid 24595:tid 24595] [client 185.46.151.62:45752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "museum.henning.org"] [uri "/wp-config.php~"] [unique_id "aptlB8_wGHvFN3FfPtZq9wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:57:33
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:57:27.760325 2026] [security2:error] [pid 26597:tid 26597] [client 185.46.151.62:60422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.caddydad.com"] [uri "/wp-config.php.save"] [unique_id "aptM18QcbLErDOR9Ua4HNwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:41:45
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:41:39.154431 2026] [security2:error] [pid 13961:tid 13969] [client 185.46.151.62:57044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pilargarciamanzanares.com"] [uri "/wp-config.php.save"] [unique_id "aptJI2MPq6Xc4uinwBNLgwAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:12:55
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:12:50.296402 2026] [security2:error] [pid 8924:tid 8924] [client 185.46.151.62:47804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frelsburg.com.cajunfriedturkey.com"] [uri "/wp-config.php.bak"] [unique_id "aptCYpHfs4Cj7WSRaJ2N2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:41:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:41:30.314954 2026] [security2:error] [pid 7144:tid 7144] [client 185.46.151.62:56024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.naturalacu.com"] [uri "/wp-config.php~"] [unique_id "aps7Co3Csd6nhvv05SQmDQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-04 21:32:24
(11 hours ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:14:55
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.46.151.62 (185-46-151-62.net.gigatrans.ua): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:14:48.926947 2026] [security2:error] [pid 15815:tid 15815] [client 185.46.151.62:58832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rockinr.org"] [uri "/wp-config.php.swp"] [unique_id "aps0yID4PUDVP5PnvnAsawAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack