๐ฉ๐ช
LRob
2026-09-18 08:46:30
(1 day ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /api/session/properties | 2026-09-18 08:46 UTC
show less
Bad Web Bot
๐บ๐ธ
mnsf
2026-09-18 03:05:07
(1 day ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-17 05:20:47
(2 days ago)
csagent: score 18.5: wp-config backup grab x2, 404 noise floor x2; 1 domain(s) in 37s
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 04:17:53
(2 days ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 187 ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 187.52.121.236 - - \[17/Sep/2026:06:17:51 +0200\] "GET /wp-config.php.save HTTP/1.1" 404 88917 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 00:53:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 187.52.121.236 (srv1917336.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.52.121.236 (srv1917336.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 20:53:56.156931 2026] [security2:error] [pid 632089:tid 632089] [client 187.52.121.236:50886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mytapt.com"] [uri "/wp-config.php.save"] [unique_id "aqs6JCE3ocxtlkYb14ksqAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-15 07:17:50
(4 days ago)
[TueSep1509:17:44.9399202026][security2:error][pid2928941:tid2928989][client187.52.121.236:0]ModSecu ...
show more
[TueSep1509:17:44.9399202026][security2:error][pid2928941:tid2928989][client187.52.121.236:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autodiscover.ksmstudio.ch\"][uri\"/.git/HEAD\"][unique_id\"aqjxGMTiHBfRPpCUy6PjOQAAAEw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 04:00:05
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-15 02:50:08
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-14 10:36:33
(5 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 187.52.121.236 - - [14/Sep/2026:12:36:32 +0200] "GET /.env.bak HTTP/1.1" 301 6165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-14 06:22:34
(5 days ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 187.52.121.236 - - [14/Sep/2026:08:22:32 +0200] "GET /wp-config.php.old HTTP/1.1" 404 102924 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 06:01:26
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 187.52.121.236 (srv1917336.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.52.121.236 (srv1917336.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:01:18.856628 2026] [security2:error] [pid 20827:tid 20849] [client 187.52.121.236:34536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativedemocrat.com"] [uri "/wp-config.php.txt"] [unique_id "aqeNruHP1SvEeugfo9ND2QAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-14 04:26:22
(5 days ago)
[ti-27al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-27al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 187.52.121.236 - - [14/Sep/2026:06:26:20 +0200] "GET /wp-config.php.orig HTTP/1.1" 404 42326 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 19:55:41
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 187.52.121.236 (srv1917336.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.52.121.236 (srv1917336.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 15:55:34.713307 2026] [security2:error] [pid 25098:tid 25098] [client 187.52.121.236:38414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thenewplantation.org"] [uri "/wp-config.php.swp"] [unique_id "aqb_tsVuCkAmTW-RuWoDVgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 15:52:01
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 187.52.121.236 (srv1917336.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 187.52.121.236 (srv1917336.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:51:54.810876 2026] [security2:error] [pid 5683:tid 5683] [client 187.52.121.236:52644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eta-mct.com"] [uri "/.env"] [unique_id "aqbGmgwhqHf2vPP4E5FN6QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack