๐ณ๐ฑ
Brict IT
2026-08-22 19:16:41
(1 day ago)
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-08-22 16:20:32
(1 day ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 14:23:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:23:44.610932 2026] [security2:error] [pid 1269:tid 1269] [client 213.152.161.109:50242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jessicalevant.com"] [uri "/wp-config.txt"] [unique_id "aomw8OoHOfGE05qZf7_-WgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 13:57:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:57:38.977574 2026] [security2:error] [pid 26563:tid 26563] [client 213.152.161.109:40068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ismaelcavazos.com"] [uri "/blog/wp-config.php"] [unique_id "aomq0m79Fx_25DU90r-59QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 12:25:50
(1 day ago)
213.152.161.109 - - [22/Aug/2026:07:25:39 -0500] "GET /.env~ HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Mac ...
show more
213.152.161.109 - - [22/Aug/2026:07:25:39 -0500] "GET /.env~ HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.27" 104.23.168.106
213.152.161.109 - - [22/Aug/2026:07:25:40 -0500] "GET /.env.swp HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.4.22" 104.23.166.31
213.152.161.109 - - [22/Aug/2026:07:25:48 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.4.22" 104.23.168.106
213.152.161.109 - - [22/Aug/2026:07:25:48 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Ubuntu; Linux x86_64; rv:127.0) Gecko/20100101 Firefox/127.0" 104.23.166.31
213.152.161.109 - - [22/Aug/2026:07:25:48 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KH
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-22 10:35:02
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.txt (+2 more)
show less
Hacking
Web App Attack
Anonymous
2026-08-22 10:33:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.OLD HTTP/1.1, GET /wp-config.php.bak HTTP ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.OLD HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /wp-config.old HTTP/1.1, GET /.wp-config.php.swp HTTP/1.1, GET /wp-config.inc HTTP/1.1, GET /wp-config.php.orig HTTP/1.1, GET /wp-config-sample.php HTTP/1.1, GET /wp-config.php.dist HTTP/1.1, GET /wp-config.php.old HTTP/1.1, GET /wp-config.php.BAK HTTP/1.1, GET /wp-config.php.inc HTTP/1.1, GET /wp-config.php HTTP/1.1, GET /wp-config.txt HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /wp-config-backup.txt HTTP/1.1, GET /wp-config.php.html HTTP/1.1, GET /wp-config.php.SAVE HTTP/1.1, GET /wp-config.php.original HTTP/1.1, GET /wp-config.backup HTTP/1.1, GET /wp-config.php.bk HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.txt HTTP/1.1, GET /wp-config.php-backup HTTP/1.1, GET /wp-config.php.save HTTP/1.1, GET /wp-config.php_orig HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 09:17:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:17:42.992278 2026] [security2:error] [pid 16305:tid 16305] [client 213.152.161.109:37730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fetchamreadingroom.org"] [uri "/wp-config.php.inc"] [unique_id "aolpNiMKjeiJwLD7iTKabQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-22 05:43:10
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
Apache
2026-08-22 05:00:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 5 in the last 300 secs (CF ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-22 03:35:05
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
gadix
2026-08-22 02:46:12
(1 day ago)
[22/Aug/2026:04:46:00.469092 +0200] aokNaAkaKPMlrxWmMKP7jQAAAAI 213.152.161.109 33520 127.0.0.1 7081 ...
show more
[22/Aug/2026:04:46:00.469092 +0200] aokNaAkaKPMlrxWmMKP7jQAAAAI 213.152.161.109 33520 127.0.0.1 7081
[22/Aug/2026:04:46:01.045420 +0200] aokNaV0N-Uj7Z5HUMZuW7AAAAAA 213.152.161.109 33540 127.0.0.1 7081
[22/Aug/2026:04:46:12.015841 +0200] aokNdOpuvdi-HxYqPLNTCQAAAAY 213.152.161.109 45774 127.0.0.1 7081
...
show less
Web App Attack
๐จ๐ฆ
Mediashaker
2026-08-22 01:24:00
(2 days ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 213.152.161.109 (-)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-21 23:18:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.161.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 19:18:38.710717 2026] [security2:error] [pid 18308:tid 18308] [client 213.152.161.109:54420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.agworldmissions.org"] [uri "/wp-config.php.inc"] [unique_id "aojczvsad4nrfoJ0bhuJOwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
pengpeng
2026-07-26 19:21:11
(4 weeks ago)
monitor: on VM-0-7-ubuntu | port: 17083 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporte ...
show more
monitor: on VM-0-7-ubuntu | port: 17083 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan