🇺🇸
TPI-Abuse
2026-09-22 20:21:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:20:58.706154 2026] [security2:error] [pid 6925:tid 6925] [client 191.252.81.32:36462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cinderellanapkins.com"] [uri "/wp-config.php.bak"] [unique_id "arLjKn1dw20mi_laiR0epwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-22 19:34:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:34:51.633105 2026] [security2:error] [pid 14427:tid 14427] [client 191.252.81.32:44842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vibratingharvard.com"] [uri "/wp-config.php.bak"] [unique_id "arLYW0Crjh__EvDoB_BpwwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-22 19:02:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:02:10.098373 2026] [security2:error] [pid 11583:tid 11583] [client 191.252.81.32:37468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yubagals.com"] [uri "/wp-config.php.bak"] [unique_id "arLQso8PfMLE3qJVNBoGLgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-22 17:16:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:15:59.620925 2026] [security2:error] [pid 30055:tid 30055] [client 191.252.81.32:59602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "budhanscom.com"] [uri "/wp-config.php.bak"] [unique_id "arK3z3Vfsls9dCX0CayONgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-22 16:29:33
(1 day ago)
191.252.81.32 - - [22/Sep/2026:18:29:17 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 555 "-" "-"
191 ...
show more
191.252.81.32 - - [22/Sep/2026:18:29:17 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 555 "-" "-"
191.252.81.32 - - [22/Sep/2026:18:29:18 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4452 "-" "-"
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-22 16:24:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:23:59.371469 2026] [security2:error] [pid 12073:tid 12073] [client 191.252.81.32:45302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starfrontiers.com"] [uri "/wp-config.php.bak"] [unique_id "arKrn5NXLDClKW1v2_Y7cgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-22 13:47:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:46:55.607744 2026] [security2:error] [pid 32621:tid 32621] [client 191.252.81.32:49540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airdriedrivingschool.com"] [uri "/wp-config.php.bak"] [unique_id "arKGzzb_LpdSaErvkyndJwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-22 12:45:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:45:53.205467 2026] [security2:error] [pid 19227:tid 19259] [client 191.252.81.32:52790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayareajazzandbluesicians.com"] [uri "/wp-config.php.bak"] [unique_id "arJ4gbXAZ9q6K_C1V6k_vAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-22 04:42:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:42:36.269674 2026] [security2:error] [pid 16793:tid 16813] [client 191.252.81.32:50592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siriuspharmaceuticals.com"] [uri "/.env"] [unique_id "arIHPPAclxjHTnRe0c3yUQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-22 04:16:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): ...
show more
(mod_security) mod_security (id:210492) triggered by 191.252.81.32 (vpshost6358.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:16:21.307693 2026] [security2:error] [pid 17689:tid 17689] [client 191.252.81.32:58996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ballast-capital.com"] [uri "/.env"] [unique_id "arIBFW0-1YU6D9jFaU16JwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇬
securejdprop
2026-09-22 03:56:41
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-env-access.
Hacking
Web App Attack