🇩🇪
on-com
2026-09-05 17:12:19
(32 minutes ago)
URL scan
Brute-Force
Web App Attack
🇺🇸
TAY
2026-09-05 16:06:04
(1 hour ago)
208.97.153.153 - - [06/Sep/2026:00:05:00 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6146 "-" "Mozi ...
show more
208.97.153.153 - - [06/Sep/2026:00:05:00 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6146 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
208.97.153.153 - - [06/Sep/2026:00:05:02 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 48454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
208.97.153.153 - - [06/Sep/2026:00:05:31 +0800] "GET /wp-config.php~ HTTP/1.1" 301 6143 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
208.97.153.153 - - [06/Sep/2026:00:05:33 +0800] "GET /wp-config.php~ HTTP/1.1" 404 48454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
208.97.153.153 - - [06/Sep/2026:00:05:59 +0800] "GET /wp-config.php.save HTTP/1.1" 301 6147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, li
...
show less
Brute-Force
🇺🇸
TAY
2026-09-05 14:49:19
(2 hours ago)
208.97.153.153 - - [05/Sep/2026:22:49:09 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 34922 "-" "Moz ...
show more
208.97.153.153 - - [05/Sep/2026:22:49:09 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
208.97.153.153 - - [05/Sep/2026:22:49:11 +0800] "GET /wp-config.php~ HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
208.97.153.153 - - [05/Sep/2026:22:49:13 +0800] "GET /wp-config.php.save HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
208.97.153.153 - - [05/Sep/2026:22:49:14 +0800] "GET /wp-config.php.old HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
208.97.153.153 - - [05/Sep/2026:22:49:15 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KH
...
show less
Brute-Force
🇮🇹
CoreTech srl
2026-09-05 13:13:56
(4 hours ago)
cloudlinux2 fail2ban: 2026-09-05 15:08:50,257 fail2ban.filter [1594]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-05 15:08:50,257 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.146.55.216 - 2026-09-05 15:08:49cloudlinux2 fail2ban: 2026-09-05 15:09:11,170 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 208.97.153.153 - 2026-09-05 15:09:11cloudlinux2 fail2ban: 2026-09-05 15:09:08,028 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 208.97.153.153 - 2026-09-05 15:09:07cloudlinux2 fail2ban: 2026-09-05 15:09:15,431 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Ban 208.97.153.153cloudlinux2 fail2ban: 2026-09-05 15:09:15,103 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 208.97.153.153 - 2026-09-05 15:09:15cloudlinux2 fail2ban: 2026-09-05 15:09:15,438 fail2ban.filter [1594]: INFO [recidive] Found 208.97.153.153 - 2026-09-05 15:09:15cloudlinux2 fail2ban: 2026-09-05 15:09:31,356 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 185.223.152.213 - 2026-09-05 15:09:31cloudlinux2 fail2ban: 202
show less
Web App Attack
🇩🇪
LRob
2026-09-05 13:12:54
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak | 2026-09-05 13:12 UTC
show less
Hacking
Web App Attack
🇲🇾
Rizzy
2026-09-05 11:18:25
(6 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇬🇧
Apache
2026-09-05 09:23:04
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (US/United States/vps40361.dream ...
show more
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (US/United States/vps40361.dreamhostps.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
Anonymous
2026-09-05 07:13:12
(10 hours ago)
[PathScanning] Path scanning/probing detected: Backup file probe (path: /wp-config.php.bak) | [Confi ...
show more
[PathScanning] Path scanning/probing detected: Backup file probe (path: /wp-config.php.bak) | [ConfigAccess] Configuration file access attempt: Config file access attempt: wp-config.php; Config file access attempt: wp-config.php.bak; Config file access attempt: config.php (path: /wp-config.php.bak)
show less
Port Scan
Hacking
Web App Attack
🇬🇧
Apache
2026-09-05 05:47:31
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (US/United States/vps40361.dream ...
show more
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (US/United States/vps40361.dreamhostps.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
🇩🇪
paissangroup
2026-09-05 05:35:24
(12 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 04:20:07
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (vps40361.dreamhostps.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (vps40361.dreamhostps.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 00:20:04.503494 2026] [security2:error] [pid 3842992:tid 3842997] [client 208.97.153.153:60560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.visionforandfromchildren.org"] [uri "/wp-config.php.bak"] [unique_id "apuYdJDYVZGnvX6lqI5CkQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 03:34:09
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (vps40361.dreamhostps.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (vps40361.dreamhostps.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 23:34:04.947825 2026] [security2:error] [pid 1189:tid 1189] [client 208.97.153.153:40632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monogay.org"] [uri "/wp-config.php.bak"] [unique_id "apuNrId6LNLoRCNs1-LkDAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
HostingGroup
2026-09-05 03:26:53
(14 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 3. First blocked: 2026-09-05.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 02:55:55
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (vps40361.dreamhostps.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 208.97.153.153 (vps40361.dreamhostps.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:55:51.450376 2026] [security2:error] [pid 24205:tid 24205] [client 208.97.153.153:45564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fatcavestudios.fatcavemedia.com"] [uri "/wp-config.php.bak"] [unique_id "apuEtwhu1GVwzkYgER7dSQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-05 01:30:36
(16 hours ago)
WordPress config file probe
Web App Attack