๐บ๐ธ
TPI-Abuse
2026-09-22 10:58:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:58:54.700103 2026] [security2:error] [pid 25912:tid 25912] [client 209.58.182.179:46622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "disenowebprofesional.com"] [uri "/wp-config.php.bak"] [unique_id "arJfboWo_wXnBqXER1Xj-wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:27:24
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:27:18.104232 2026] [security2:error] [pid 412419:tid 412419] [client 209.58.182.179:44670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "admcolumbus.com"] [uri "/wp-config.php.bak"] [unique_id "arI75u_QMgx8hjYsT9w5jAAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 02:16:16
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:16:09.377517 2026] [security2:error] [pid 4176:tid 4176] [client 209.58.182.179:36444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "piments.com"] [uri "/.env"] [unique_id "arHk6auvvD5d7SI-i1czsgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-29 06:03:13
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 02:03:06.117701 2025] [security2:error] [pid 19766:tid 19766] [client 209.58.182.179:58480] [client 209.58.182.179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pakistanvision.com"] [uri "/wp-config.phpold"] [unique_id "aBBrmqlMDfKAt-Ogn-ywtwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-28 22:37:18
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 28 18:37:13.177626 2025] [security2:error] [pid 2239:tid 2249] [client 209.58.182.179:33688] [client 209.58.182.179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ethicmark.org"] [uri "/wp-config.php.orig"] [unique_id "aBADGczI79caBJce1Rm5_QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-04-25 16:31:38
(1 year ago)
Cloudflare WAF: Request Path: /wp-config.php.bkp Request Query: Host: whk.elhacker.net userAgent: ...
show more
Cloudflare WAF: Request Path: /wp-config.php.bkp Request Query: Host: whk.elhacker.net userAgent: Action: block Source: firewallManaged ASN Description: LEASEWEB-APAC-SIN-11 LEASEWEB SINGAPORE PTE. LTD. Country: SG Method: GET Timestamp: 2025-04-25T16:31:38Z ruleId: 7994335d116849f7a0ab6b771d1d0db7. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-25 09:47:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 05:47:53.670355 2025] [security2:error] [pid 3229200:tid 3229200] [client 209.58.182.179:34378] [client 209.58.182.179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitalitywebb.com"] [uri "/wp-config.bak"] [unique_id "aAtaSWrg3IK9uiHvgJekHgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-04-24 20:06:18
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-04-24 00:06:15
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-04-23 21:26:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210730) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 17:26:39.450498 2025] [security2:error] [pid 14206:tid 14206] [client 209.58.182.179:34392] [client 209.58.182.179] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ezekielproductions.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ezekielproductions.com"] [uri "/wp-config.backup"] [unique_id "aAlbD3CMQnQR0ZHqC-jk-QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-04-23 20:06:15
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-04-23 15:39:24
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 11:39:21.386180 2025] [security2:error] [pid 2538461:tid 2538461] [client 209.58.182.179:38676] [client 209.58.182.179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "individualhealth.com"] [uri "/wp-config.php.backup"] [unique_id "aAkJqahRRAT0tQt7-LQ3KgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 03:54:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210730) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 23:54:00.717408 2025] [security2:error] [pid 13905:tid 13920] [client 209.58.182.179:44426] [client 209.58.182.179] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||seips.org|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "seips.org"] [uri "/wp-config.backup"] [unique_id "aAhkWBn1_RhE7pLNQG3HOAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 02:34:50
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 22:34:43.584915 2025] [security2:error] [pid 4812:tid 4812] [client 209.58.182.179:44596] [client 209.58.182.179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gwenwaltersartrep.com"] [uri "/wp-config.php.backup"] [unique_id "aAhRw1j2GW4z8ix_rUIDkgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 01:58:37
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 209.58.182.179 (sg01.server.plus): 1 in the las ...
show more
(mod_security) mod_security (id:210730) triggered by 209.58.182.179 (sg01.server.plus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 21:58:33.303828 2025] [security2:error] [pid 2353:tid 2353] [client 209.58.182.179:43256] [client 209.58.182.179] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||accu-tuner.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "accu-tuner.com"] [uri "/wp-config.backup"] [unique_id "aAhJSXmgswJTqbB0TZu-RQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack