๐บ๐ธ
TPI-Abuse
2026-09-25 10:53:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:52:56.240877 2026] [security2:error] [pid 13715:tid 13715] [client 2001:8d8:5ff:5f:82:165:87:227:41686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unilabkenya.com"] [uri "/.env"] [unique_id "arZSiJ_kU5z4wcsJlQzQ2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 10:13:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:13:05.682580 2026] [security2:error] [pid 11619:tid 11619] [client 2001:8d8:5ff:5f:82:165:87:227:43650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cityslickerstomp.info"] [uri "/.env"] [unique_id "arZJMUHPmoQbtqc72qyhPwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:00:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:00:20.343878 2026] [security2:error] [pid 1320751:tid 1320751] [client 2001:8d8:5ff:5f:82:165:87:227:42004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jonesypop.com"] [uri "/wp-config.php.bak"] [unique_id "arLsZLsmFK4B26Oq5kX1wgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:46:25
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:46:21.293601 2026] [security2:error] [pid 32464:tid 32464] [client 2001:8d8:5ff:5f:82:165:87:227:43496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stbms.com"] [uri "/wp-config.php.bak"] [unique_id "arLbDb97PXeA6hxySN1asgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:51:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:50:56.150989 2026] [security2:error] [pid 20978:tid 20978] [client 2001:8d8:5ff:5f:82:165:87:227:46276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gotdt.com"] [uri "/wp-config.php.bak"] [unique_id "arLOEFODLHvnye3mO-kNrQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:07:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:07:14.656111 2026] [security2:error] [pid 13764:tid 13764] [client 2001:8d8:5ff:5f:82:165:87:227:41656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohwaitiforgot.com"] [uri "/wp-config.php.bak"] [unique_id "arLD0k1J2zHk_b7HuIZZuwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:09:38
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:09:30.552426 2026] [security2:error] [pid 1830:tid 1830] [client 2001:8d8:5ff:5f:82:165:87:227:60574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hardcountryrock.com"] [uri "/wp-config.php.bak"] [unique_id "arK2SvD1NYhrwr2f1V_BuAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:18:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:18:10.646528 2026] [security2:error] [pid 1977:tid 1977] [client 2001:8d8:5ff:5f:82:165:87:227:39868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwieser.com"] [uri "/wp-config.php.bak"] [unique_id "arKcMmKXFZxd5urJ90fzygAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:23:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:23:45.308607 2026] [security2:error] [pid 13718:tid 13789] [client 2001:8d8:5ff:5f:82:165:87:227:54782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "la.productions"] [uri "/wp-config.php.bak"] [unique_id "arJzUU4l_-HKySCvTYYWPQAAAgI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:28:51
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:949110) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:28:46.998822 2026] [security2:error] [pid 23884:tid 23884] [client 2001:8d8:5ff:5f:82:165:87:227:57692] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahaabooking.com"] [uri "/wp-config.php.bak"] [unique_id "arJmbth_sz8miA4MJN1B1AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:24:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:24:01.406794 2026] [security2:error] [pid 615:tid 636] [client 2001:8d8:5ff:5f:82:165:87:227:52086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "utahhoaservices.com"] [uri "/wp-config.php.bak"] [unique_id "arJXQc-OAFL6V8CCXBcb1QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 02:15:42
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.cli ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:87:227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:15:34.574028 2026] [security2:error] [pid 2113:tid 2113] [client 2001:8d8:5ff:5f:82:165:87:227:38956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.env"] [unique_id "arHkxrfabORCXe48eNTUgwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-13 14:03:54
(1 year ago)
Failed Wordpress Logins
Web App Attack
๐ฉ๐ช
LRob
2025-04-12 18:00:13
(1 year ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
LRob
2025-04-12 11:45:06
(1 year ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack