🇺🇸
TPI-Abuse
2026-09-08 08:49:13
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:49:08.282676 2026] [security2:error] [pid 28249:tid 28249] [client 2.180.2.216:42754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.earthwormensemble.doublenaughtspycar.com"] [uri "/wp-config.php.bak"] [unique_id "ap_MBMg2UgIZ3UmK9S7PnwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-08 08:41:10
(1 hour ago)
2.180.2.216 - - [08/Sep/2026:16:40:55 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6146 "-" "Mozilla ...
show more
2.180.2.216 - - [08/Sep/2026:16:40:55 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6146 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2.180.2.216 - - [08/Sep/2026:16:40:56 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 48454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2.180.2.216 - - [08/Sep/2026:16:41:04 +0800] "GET /wp-config.php~ HTTP/1.1" 301 6143 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2.180.2.216 - - [08/Sep/2026:16:41:05 +0800] "GET /wp-config.php~ HTTP/1.1" 404 48454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2.180.2.216 - - [08/Sep/2026:16:41:07 +0800] "GET /wp-config.php.save HTTP/1.1" 301 6147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrom
...
show less
Brute-Force
🇩🇪
Vegascosmetics
2026-09-08 06:59:43
(3 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 73>=65, Abuse 77, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-08 06:39:19
(3 hours ago)
10 hits, proto=tcp, ports=443,80
Port Scan
Hacking
🇬🇧
Apache
2026-09-08 06:38:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (IR/Iran/-): 5 in the last 300 secs ...
show more
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (IR/Iran/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇧🇪
taivas.nl
2026-09-08 06:38:01
(3 hours ago)
SYNScan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:37:36
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:37:30.029824 2026] [security2:error] [pid 12849:tid 12849] [client 2.180.2.216:35264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coretherapyassoc.com.praemiumtech.com"] [uri "/wp-config.php.bak"] [unique_id "ap906k0UqSCSNRkNuTOrBgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:13:20
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:13:15.616727 2026] [security2:error] [pid 1026614:tid 1026637] [client 2.180.2.216:40626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.plumeraproductions.com"] [uri "/wp-config.php.bak"] [unique_id "ap9vO-WNzL2fmfkVZUh14wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:51:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:51:10.661802 2026] [security2:error] [pid 16653:tid 16653] [client 2.180.2.216:46892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "museum.henning.org"] [uri "/wp-config.php.bak"] [unique_id "ap9qDqvy_8xzfIwcZ4DcMgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 01:40:49
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-08 01:04:10
(8 hours ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.iatrika-analosima.gr; logs=/var/log/httpd/domains/ia ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.iatrika-analosima.gr; logs=/var/log/httpd/domains/iatrika-analosima.gr.log; samples=/wp-config.php.bak | /wp-config.php~ | /wp-config.php.save
show less
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-08 01:03:37
(9 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
🇧🇪
cmbplf
2026-09-08 00:36:23
(9 hours ago)
981 requests with url.path *.php.bak
678 requests with url.path */debug.log
678 requests with url ...
show more
981 requests with url.path *.php.bak
678 requests with url.path */debug.log
678 requests with url.path *debug.log
477 requests with url.path *.git/*
307 requests with url.path /phpinfo.php
241 requests with url.path */yarn.lock
241 requests with url.path */package.json
240 requests with url.path */composer.lock
238 requests with url.path *.sql.gz
236 requests with url.path *.hg/*
235 requests with url.path */error.log
232 requests with url.path */package-lock.json
231 requests with url.path */composer.json
230 requests with url.path *.svn/*
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 23:28:11
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:28:06.338798 2026] [security2:error] [pid 25601:tid 25601] [client 2.180.2.216:39002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.doreenkimura.com.misscharlottemusic.com"] [uri "/wp-config.php.bak"] [unique_id "ap9IhoG35yrujSlkUXghJgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:05:53
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 2.180.2.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:05:48.800715 2026] [security2:error] [pid 4313:tid 4313] [client 2.180.2.216:37886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharawi-gum.com"] [uri "/wp-config.php.bak"] [unique_id "ap9DTI8ZiXfrkDfWS0g8zQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack