๐บ๐ธ
TPI-Abuse
2026-09-24 06:58:22
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t- ...
show more
(mod_security) mod_security (id:210492) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t-mobile.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:58:15.689394 2026] [security2:error] [pid 6180:tid 6180] [client 188.146.16.27:57983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boatregistrationdelaware.com"] [uri "/wp-config.php.bak"] [unique_id "arTKB4VQ4_5XcTQEHa44BwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:20:31
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t- ...
show more
(mod_security) mod_security (id:210730) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t-mobile.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:20:24.406860 2026] [security2:error] [pid 16845:tid 16845] [client 188.146.16.27:1906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dogarttoday.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dogarttoday.com"] [uri "/error.log"] [unique_id "arRQqDMPYkzPBnXejIpq6wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:10:57
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t- ...
show more
(mod_security) mod_security (id:225170) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t-mobile.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:10:52.265187 2026] [security2:error] [pid 15437:tid 15437] [client 188.146.16.27:57941] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||renjunews.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "renjunews.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arRAXEkRt_oWRQmuwPEBogAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-23 21:05:17
(2 weeks ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: / | 2026-09-23 21:05 UTC
show less
Bad Web Bot
๐บ๐ธ
nyt
2026-09-23 19:18:56
(2 weeks ago)
Sensitive File Probe
Web App Attack
Anonymous
2026-09-23 19:06:41
(2 weeks ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
yitzhaq
2026-09-23 17:08:22
(2 weeks ago)
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /wp-config.php.bak HTTP/2.0" 404 362 "-" "curl/8 ...
show more
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /wp-config.php.bak HTTP/2.0" 404 362 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /wp-config.php~ HTTP/2.0" 404 362 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:18 +0200] "GET / HTTP/2.0" 302 317 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:19 +0200] "GET / HTTP/2.0" 302 317 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /error.log HTTP/2.0" 404 362 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /wp-content/debug.log HTTP/2.0" 404 362 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /wp-config.php HTTP/2.0" 404 341 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /.env HTTP/2.0" 404 362 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /.git/config HTTP/2.0" 403 369 "-" "curl/8.7.1"
188.146.16.27 - - [23/Sep/2026:19:08:21 +0200] "GET /error_log HTTP/2.0" 404 362 "-" "curl/8.7.1"
show less
Web App Attack
Brute-Force
๐ง๐ช
madeit
2026-09-23 15:36:18
(2 weeks ago)
Web App Attack
๐ง๐ท
Halux
2026-09-23 14:56:24
(2 weeks ago)
188.146.16.27 Probing protected path or service
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-23 14:44:31
(2 weeks ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:31:13
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t- ...
show more
(mod_security) mod_security (id:210730) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t-mobile.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:31:07.565653 2026] [security2:error] [pid 8810:tid 8810] [client 188.146.16.27:18101] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arapi.org|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arapi.org"] [uri "/wp-content/debug.log"] [unique_id "arPiq_PWWrUYwz34vdN3vwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-09-23 03:52:50
(2 weeks ago)
WP Config Probe
Web App Attack
Anonymous
2026-09-23 03:05:18
(2 weeks ago)
Blocked: Reason='Suspicious traffic score=100 (review-based detection)'; Requests=25
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 02:33:41
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t- ...
show more
(mod_security) mod_security (id:210492) triggered by 188.146.16.27 (188.146.16.27.mobile.internet.t-mobile.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:33:35.523262 2026] [security2:error] [pid 2360:tid 2360] [client 188.146.16.27:57942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-bahamas.com"] [uri "/wp-config.php"] [unique_id "arM6f5O6IUJldWQYlLbIewAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-23 02:30:08
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack