๐บ๐ธ
TPI-Abuse
2026-05-21 16:57:13
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 212.18.127.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.18.127.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 12:57:09.357587 2026] [security2:error] [pid 26918:tid 26918] [client 212.18.127.58:49929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eye7graphics.com"] [uri "/wp-config.php~"] [unique_id "ag85ZUVlwF2em0xZ9Qk-5gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 16:34:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 212.18.127.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.18.127.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:34:15.691142 2026] [security2:error] [pid 1140:tid 1140] [client 212.18.127.58:13113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "opticasprisma.com"] [uri "/wp-config.php.old"] [unique_id "ag3ih2oPr8tRBm0IxS9MBAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 12:54:27
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 212.18.127.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.18.127.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:54:19.820817 2026] [security2:error] [pid 1613:tid 1613] [client 212.18.127.58:63651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peacecampus.org"] [uri "/wp-config.php.bak"] [unique_id "ag2u-xOx672r9kbPds6-SgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-04-30 20:11:19
(1 month ago)
[ThuApr3022:11:15.0704482026][security2:error][pid4107206:tid4107962][client212.18.127.58:0]ModSecur ...
show more
[ThuApr3022:11:15.0704482026][security2:error][pid4107206:tid4107962][client212.18.127.58:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchedphrase\"wp-config.php\"atARGS:img.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"135\"][id\"344360\"][rev\"5\"][msg\"Atomicorp.comWAFRules:UnauthorizedOperatingSystemFileAccessAttempt\"][data\"MatchedData:wp-config.phpfoundwithinARGS:img:../wp-config.php\"][severity\"CRITICAL\"][tag\"attack-lfi\"][hostname\"mondo-it.ch\"][uri\"/wp-admin/admin-ajax.php\"][unique_id\"afO3YpbaoKfgp5qd3XlOVQAAAEc\"]
show less
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-03-11 12:21:00
(3 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ซ๐ท
tilellit.pro
2026-03-01 20:05:50
(3 months ago)
Fail2Ban banned 212.18.127.58 for security violations in jail wp-armour. Log: 2026/03/01 20:05:50 [e ...
show more
Fail2Ban banned 212.18.127.58 for security violations in jail wp-armour. Log: 2026/03/01 20:05:50 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 212.18.127.58 | Target: wplogin" , client: 212.18.127.58, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-19 11:24:55
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 212.18.127.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.18.127.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 06:24:48.492958 2025] [security2:error] [pid 24779:tid 24779] [client 212.18.127.58:19539] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "aUU2AO04aGS106Y3UCL5JQAAAA4"], referer: https://slate.com/technology/2006/06/the-godfather-the-game-reviewed.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HandyTreff.de
2025-12-04 00:58:07
(6 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -20.112 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -20.112 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.1471.1
show less
Bad Web Bot
Web App Attack