๐บ๐ธ
TPI-Abuse
2026-09-22 22:37:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:37:14.954084 2026] [security2:error] [pid 2079:tid 2079] [client 212.52.180.181:48294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ainalea.com"] [uri "/wp-config.php.bak"] [unique_id "arMDGhoPMEKjkHnWArxnTAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 22:32:35
(1 day ago)
Automatically blocked after 1 security event. Observed repeated web application attack probes. Sourc ...
show more
Automatically blocked after 1 security event. Observed repeated web application attack probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:39:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:39:41.611250 2026] [security2:error] [pid 8807:tid 8807] [client 212.52.180.181:54850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notearsweb.com"] [uri "/wp-config.php.bak"] [unique_id "arL1nTllueTGiFNO5afTJgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 20:23:30
(1 day ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 212.52.180.181 - - [22/Sep/2026:22:23:29 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 457 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:14:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:14:52.703583 2026] [security2:error] [pid 16534:tid 16748] [client 212.52.180.181:35390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vaprivatecollection.com"] [uri "/wp-config.php.bak"] [unique_id "arLhvE4D9BfKmCVpJATbzgAAAlU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:58:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:57:59.406672 2026] [security2:error] [pid 28450:tid 28450] [client 212.52.180.181:53374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeremyscraig.com"] [uri "/wp-config.php.bak"] [unique_id "arLdx4IEgF55fB8RkZ3toAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:23:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:23:42.648782 2026] [security2:error] [pid 28057:tid 28057] [client 212.52.180.181:40896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jbcllcnet.com"] [uri "/wp-config.php.bak"] [unique_id "arLHro56kHiyv3Z_oQjJ0AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-22 17:00:35
(1 day ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:24:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:24:44.825963 2026] [security2:error] [pid 17014:tid 17014] [client 212.52.180.181:43446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalmappinginc.com"] [uri "/wp-config.php.bak"] [unique_id "arKrzBrHI3_e38p29y-bjQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-22 14:48:24
(1 day ago)
SmallGuard.fr/Prestashop Empty User Agent
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:00:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:00:01.669136 2026] [security2:error] [pid 13716:tid 13742] [client 212.52.180.181:44108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmykdesign.com"] [uri "/wp-config.php.bak"] [unique_id "arKJ4aJdpEbRpM-GHp8VSQAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:43:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:43:50.299895 2026] [security2:error] [pid 8621:tid 8621] [client 212.52.180.181:36792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "encoremtmorris.com"] [uri "/info/jamfest//wp-config.php.bak"] [unique_id "arKGFmTnCrCc_-T0Dg1RzgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:17:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:16:55.485264 2026] [security2:error] [pid 32479:tid 32479] [client 212.52.180.181:47208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainararattrek.com"] [uri "/wp-config.php.bak"] [unique_id "arJ_xypakpGf2RKa3o8OkQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:03:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 212.52.180.181 (da.cartmen.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:03:18.660675 2026] [security2:error] [pid 7796:tid 7796] [client 212.52.180.181:60712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myriadpubs.com"] [uri "/wp-config.php.bak"] [unique_id "arJuhrUap2UnenB3_oaCNwAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ecode hosting
2026-09-22 08:45:06
(1 day ago)
Domain : gnsskirala.com
Rule : hack
2026-09-22 08:43:23 10.100.1.20 GET /wp-config.php.bak - 80 - 21 ...
show more
Domain : gnsskirala.com
Rule : hack
2026-09-22 08:43:23 10.100.1.20 GET /wp-config.php.bak - 80 - 212.52.180.181 HTTP/1.1 - - gnsskirala.com 301 0 0 347 70 500 - -
show less
Hacking
SQL Injection
Brute-Force