🇺🇸
TPI-Abuse
2026-09-15 06:59:21
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:59:14.887444 2026] [security2:error] [pid 32290:tid 32290] [client 187.124.77.172:54908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertherapyoc.com"] [uri "/wp-config.php.bak"] [unique_id "aqjswvAyvTPN9SwrfFX5dgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
[email protected]
2026-09-15 00:19:54
(13 hours ago)
187.124.77.172 - - [15/Sep/2026:00:19:53 +0000] "GET /.env.txt HTTP/1.1" 404 327 "-" "Mozilla/5.0 (W ...
show more
187.124.77.172 - - [15/Sep/2026:00:19:53 +0000] "GET /.env.txt HTTP/1.1" 404 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
187.124.77.172 - - [15/Sep/2026:00:19:53 +0000] "GET /.git/config HTTP/1.1" 404 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
187.124.77.172 - - [15/Sep/2026:00:19:53 +0000] "GET /.git/HEAD HTTP/1.1" 404 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇵🇱
Budyn
2026-09-14 18:30:49
(19 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.goblinpot.space | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 04:40:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210730) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 00:40:53.993837 2026] [security2:error] [pid 4981:tid 4981] [client 187.124.77.172:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||duct.cloudex.click|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "duct.cloudex.click"] [uri "/backup.sql"] [unique_id "aqd61cK3QDWVK4zUFVMH5wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-14 01:32:13
(1 day ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 187 ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 187.124.77.172 - - \[14/Sep/2026:03:32:11 +0200\] "GET /phpinfo.php HTTP/1.1" 301 5786 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 21:28:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:28:45.380580 2026] [security2:error] [pid 18118:tid 18118] [client 187.124.77.172:47836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usaenquirer.com"] [uri "/.hg/store/00manifest.i"] [unique_id "aqcVjUZjzkVUq-eOEFLjygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 09:28:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:28:11.519399 2026] [security2:error] [pid 8042:tid 8042] [client 187.124.77.172:39944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armorcorp.gulftelecom.com"] [uri "/wp-config.php.bak"] [unique_id "aqZsq9YY90rBu04MJO9e-AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 03:01:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 23:01:20.455080 2026] [security2:error] [pid 29828:tid 29859] [client 187.124.77.172:51050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vinylnotespodcast.com"] [uri "/wp-config.php.orig"] [unique_id "aqYSAGv6daTh7iWDgkZGPAAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:33:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:33:15.071418 2026] [security2:error] [pid 7233:tid 7233] [client 187.124.77.172:49958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenewplantation.org"] [uri "/wp-config.php.orig"] [unique_id "aqXhO2lmqKSDFOK4NyW_PQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 20:07:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 16:07:34.909637 2026] [security2:error] [pid 30109:tid 30109] [client 187.124.77.172:45132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fatcavestudios.fatcavemedia.com"] [uri "/wp-config.php~"] [unique_id "aqWxBolFcUtoWEjWxytjzAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 12:35:02
(3 days ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:43:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:43:51.245383 2026] [security2:error] [pid 16400:tid 16503] [client 187.124.77.172:38950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koalacogs.com"] [uri "/wp-config.php.save"] [unique_id "aqUe12PyILvApH7OSEI58wAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
Rauno Asp
2026-09-11 03:41:49
(4 days ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:02:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:02:21.136553 2026] [security2:error] [pid 31257:tid 31257] [client 187.124.77.172:38614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theamarals.com"] [uri "/.env.bak"] [unique_id "ap5hffYZXeMHkvpwcJUfPAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:38:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.124.77.172 (srv1452447.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:37:56.998311 2026] [security2:error] [pid 20284:tid 20284] [client 187.124.77.172:48506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "semisysteme.com"] [uri "/wp-config.php.swp"] [unique_id "ap4VdHqVWIuHSf3L0qrWygAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack