🇫🇷
dynamix
2026-09-12 22:20:55
(1 week ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 21:47:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:47:27.425801 2026] [security2:error] [pid 27797:tid 27797] [client 2001:41d0:203:4102:::43716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomasgardner.com"] [uri "/wp-config.php.bak"] [unique_id "aqXIb0_bk9RdjlwueDSRFAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-12 20:25:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇵🇫
www.gregorymariani.com
2026-09-12 17:00:42
(1 week ago)
Brute-Force
🇺🇸
TPI-Abuse
2026-09-12 16:57:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 12:57:11.171680 2026] [security2:error] [pid 5236:tid 5236] [client 2001:41d0:203:4102:::36972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.indyham.com"] [uri "/wp-config.php.save"] [unique_id "aqWEZ63aZE_7Qms7nU-lFQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-12 13:19:44
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-12 09:26:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:25:52.743398 2026] [security2:error] [pid 23941:tid 24037] [client 2001:41d0:203:4102:::38240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vinylnotespodcast.com.104ventures.com"] [uri "/wp-config.php~"] [unique_id "aqUaoGmozhmNSp9dTcD1bgAAAco"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-12 09:23:04
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/122.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 06:27:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:27:08.393464 2026] [security2:error] [pid 28959:tid 28959] [client 2001:41d0:203:4102:::50242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modalsoftware.mainstreetofficesuites.com"] [uri "/wp-config.php.save"] [unique_id "aqTwvHXojsg-ki_kDW0SAAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-12 05:21:52
(1 week ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
1gz
2026-09-12 04:37:10
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.bak
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
Admins@Storch
2026-09-12 04:20:01
(1 week ago)
OPNsense: 3 hits, proto=tcp, ports=3000
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-12 02:16:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 22:16:12.019449 2026] [security2:error] [pid 966523:tid 966523] [client 2001:41d0:203:4102:::53574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troop9weymouth.com"] [uri "/wp-config.php.bak"] [unique_id "aqS17Dp-ssIdyJ5R7rd57QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-12 00:10:39
(1 week ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-12 00:10 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 23:41:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:41d0:203:4102:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 19:41:27.283740 2026] [security2:error] [pid 2872060:tid 2872085] [client 2001:41d0:203:4102:::54292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nicholsinvest.com"] [uri "/wp-config.php.bak"] [unique_id "aqSRp6kndES6lwXZVUD7aAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack