πΊπΈ
TAY
2026-09-02 20:26:09
(6 hours ago)
188.245.115.132 - - [03/Sep/2026:04:25:55 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 55927 "-" "Mo ...
show more
188.245.115.132 - - [03/Sep/2026:04:25:55 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 55927 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.245.115.132 - - [03/Sep/2026:04:25:59 +0800] "GET /wp-config.php~ HTTP/1.1" 404 55949 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.245.115.132 - - [03/Sep/2026:04:26:01 +0800] "GET /wp-config.php.save HTTP/1.1" 404 55949 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.245.115.132 - - [03/Sep/2026:04:26:03 +0800] "GET /wp-config.php.old HTTP/1.1" 404 55949 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.245.115.132 - - [03/Sep/2026:04:26:06 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 55949 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3
...
show less
Brute-Force
π©πͺ
ghostwarriors
2026-09-02 19:20:06
(7 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
yitzhaq
2026-09-02 19:04:40
(7 hours ago)
188.245.115.132 - - [02/Sep/2026:17:22:15 +0200] "GET / HTTP/1.1" 200 4580 "-" "Mozilla/5.0 (Windows ...
show more
188.245.115.132 - - [02/Sep/2026:17:22:15 +0200] "GET / HTTP/1.1" 200 4580 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.245.115.132 - - [02/Sep/2026:21:04:22 +0200] "GET / HTTP/1.1" 200 25391 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.245.115.132 - - [02/Sep/2026:21:04:29 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 4490 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.245.115.132 - - [02/Sep/2026:21:04:36 +0200] "POST /wp-json/batch/v1 HTTP/1.1" 403 4490 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.245.115.132 - - [02/Sep/2026:07:24:21 +0200] "POST /index.php HTTP/1.1" 302 4607 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0
show less
Web App Attack
Hacking
π²πΎ
Rizzy
2026-09-02 17:21:49
(9 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-02 16:15:03
(10 hours ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 16:09:54
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients ...
show more
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 12:09:48.130100 2026] [security2:error] [pid 8117:tid 8117] [client 188.245.115.132:47544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "losbarbarosdelnorte.com"] [uri "/wp-config.php~"] [unique_id "aphKTPAr3I0TU1va2xlWhQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
SkyDancer
2026-09-02 15:58:40
(10 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
π«π·
COMAITE
2026-09-02 15:55:02
(10 hours ago)
Suspicious URL access.
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 15:47:10
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients ...
show more
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:47:06.734337 2026] [security2:error] [pid 16079:tid 16079] [client 188.245.115.132:55662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.major33.com"] [uri "/wp-config.php.save"] [unique_id "aphE-rlwHYuRRkYf5yPPbAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 15:28:10
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients ...
show more
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:28:04.234097 2026] [security2:error] [pid 32302:tid 32310] [client 188.245.115.132:47880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vinylnotespodcast.com.104ventures.com"] [uri "/wp-config.php.save"] [unique_id "aphAhGmqaDjdWeyvx7ZshwAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΉ
penguin-solutions.at
2026-09-02 14:27:29
(12 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 14:17:11
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients ...
show more
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:17:06.262435 2026] [security2:error] [pid 413:tid 413] [client 188.245.115.132:45386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rochesterhistorical.org"] [uri "/wp-config.php.bak"] [unique_id "apgv4gUaIVg0WLNUqlJnfwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 13:25:39
(13 hours ago)
BIDSODE WEBEXPLOIT 188.245.115.132 (static.132.115.245.188.clients.your-server.de)
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 13:21:31
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients ...
show more
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:21:25.977512 2026] [security2:error] [pid 11333:tid 11333] [client 188.245.115.132:46572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gracebaptisthartsville.com"] [uri "/wp-config.php.save"] [unique_id "apgi1a-6n59OkGQPXp5AQwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 12:59:11
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients ...
show more
(mod_security) mod_security (id:210492) triggered by 188.245.115.132 (static.132.115.245.188.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:59:06.215010 2026] [security2:error] [pid 16379:tid 16379] [client 188.245.115.132:56800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "engineeringarts.com"] [uri "/wp-config.php.save"] [unique_id "apgdmoxSsC2HSYUgGp4wSAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack