๐ณ๐ฑ
homeshowdomain.nl
2026-09-16 22:02:28
(9 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-15.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 03:44:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:44:16.153225 2026] [security2:error] [pid 7187:tid 7187] [client 187.77.187.12:54914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ergocorrect.com"] [uri "/wp-config.php.orig"] [unique_id "aqoQkDzQBBZK57qIEFf9bwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 02:50:45
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:06:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:06:44.474197 2026] [security2:error] [pid 7424:tid 7424] [client 187.77.187.12:33392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tcit.org"] [uri "/wp-config.php.txt"] [unique_id "aqnrpHyy3w3qG3ilDAPKsgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:06:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:06:47.335729 2026] [security2:error] [pid 19391:tid 19391] [client 187.77.187.12:52908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bikinitweets.com"] [uri "/wp-config.php.swp"] [unique_id "aql7J5XUUZtMI4r-92yn-wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 13:49:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:49:02.179814 2026] [security2:error] [pid 16075:tid 16075] [client 187.77.187.12:48034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgtek.com.smogsandiego.com"] [uri "/wp-config.php.bak"] [unique_id "aqlMziA0etL6kSedfpF3XgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:44:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:44:52.929655 2026] [security2:error] [pid 30930:tid 30930] [client 187.77.187.12:42772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "activethinkers.net"] [uri "/wp-config.php.swp"] [unique_id "aqkhpKMH1NDbkozmzRgtaAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
febrian.de
2026-09-15 05:00:47
(2 days ago)
Malicious HTTP(S) probing detected by Fail2Ban
Web App Attack
Anonymous
2026-09-15 04:37:08
(2 days ago)
Web application attack detected.
Web App Attack
Anonymous
2026-09-14 19:39:02
(2 days ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
Anonymous
2026-09-14 18:54:07
(2 days ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.blazos.com; logs=/var/log/httpd/domains/blazos.com.l ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.blazos.com; logs=/var/log/httpd/domains/blazos.com.log; samples=/wp-config.php.txt
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 14:42:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 10:42:45.662068 2026] [security2:error] [pid 5159:tid 5159] [client 187.77.187.12:57908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hierrosbernal.com"] [uri "/wp-config.php.txt"] [unique_id "aqgH5fOYPaD-bC9RaAMK0QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 13:47:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 09:47:18.346260 2026] [security2:error] [pid 20330:tid 20330] [client 187.77.187.12:35882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vansfanz.rollinchassis.com"] [uri "/wp-config.php.orig"] [unique_id "aqf65iahx9vo-MOiklzUZwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 08:05:13
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210730) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 04:05:07.955580 2026] [security2:error] [pid 355:tid 355] [client 187.77.187.12:48952] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fusionrep.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fusionrep.com"] [uri "/error.log"] [unique_id "aqeqsz-OewuwHGSWEV_6kgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 01:09:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 187.77.187.12 (srv1432081.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:09:28.961574 2026] [security2:error] [pid 16642:tid 16642] [client 187.77.187.12:53378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jennyfiore.com"] [uri "/wp-config.php.bak"] [unique_id "aqdJSGCyFzAUItdK-M8oDAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack