π©πͺ
bazter.pro
2026-08-23 06:11:00
(1 hour ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
π«π·
Stara
2026-08-23 03:37:52
(3 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 03:06:35
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:06:27.318288 2026] [security2:error] [pid 4218:tid 4218] [client 213.152.187.243:48508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spacebooger.com"] [uri "/wp-config.php.SAVE"] [unique_id "aopjs7R72ORmQ5sj5nRPNAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 01:19:25
(6 hours ago)
213.152.187.243 - - [22/Aug/2026:20:19:14 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Kubu ...
show more
213.152.187.243 - - [22/Aug/2026:20:19:14 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Kubuntu; Linux i686; rv:124.0) Gecko/20100101 Firefox/124.0" 104.23.166.84
213.152.187.243 - - [22/Aug/2026:20:19:14 -0500] "GET /.env.swp HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Fedora; Linux i686; rv:121.0) Gecko/20100101 Firefox/121.0" 104.22.109.40
213.152.187.243 - - [22/Aug/2026:20:19:14 -0500] "GET /.env~ HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/18.17763" 172.71.98.27
213.152.187.243 - - [22/Aug/2026:20:19:16 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0" 172.70.246.61
213.152.187.243 - - [22/Aug/2026:20:19:24 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0" 104.23.166.84
213.152.187.243 - - [22/Aug/2026:20:19:24 -0500] "GET /
...
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
iulianh
2026-08-22 22:16:52
(9 hours ago)
80,443
Brute-Force
SSH
π©πͺ
FeG Deutschland
2026-08-22 19:31:54
(12 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
Anonymous
2026-08-22 15:43:03
(15 hours ago)
Bot / scanning and/or hacking attempts: GET /blog/wp-config.php~ HTTP/1.1, GET /wp-config.php.bak HT ...
show more
Bot / scanning and/or hacking attempts: GET /blog/wp-config.php~ HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /wp-config.php.SAVE HTTP/1.1, GET /wp-config.php.html HTTP/1.1, GET /wp-config.php.dist HTTP/1.1, GET /blog/wp-config.php.bak HTTP/1.1, GET /wp-config.php.save HTTP/1.1, GET /wp-config.php.orig HTTP/1.1, GET /wp-config.old HTTP/1.1, GET /config.php.zip HTTP/1.1, GET /.env.bak HTTP/1.1, GET /blog/.wp-config.php.swp HTTP/1.1, GET /wordpress/wp-config.php.old HTTP/1.1, GET /wp/wp-config.php.bak HTTP/1.1, GET /wp/.wp-config.php.swp HTTP/1.1, GET /wordpress/wp-config.php.bak HTTP/1.1, GET /blog/wp-config.php.save HTTP/1.1, GET /wordpress/wp-config.php HTTP/1.1, GET /.env HTTP/1.1, GET /home/kokomo-WORDPRESS.txt HTTP/1.1
show less
Hacking
Web App Attack
π©πͺ
LRob
2026-08-22 14:17:51
(17 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php (+1 more)
show less
Hacking
Web App Attack
πͺπΈ
pipeline.es
2026-08-22 12:51:19
(18 hours ago)
Web scanning / probing for vulnerable paths | URL: /wp-config.php.bk | Evidence: hotrawo.com 213.152 ...
show more
Web scanning / probing for vulnerable paths | URL: /wp-config.php.bk | Evidence: hotrawo.com 213.152.187.243 - - [22/Aug/2026:14:50:25 +0200] \"GET /wp-config.php.bk HTTP/1.1\" 403 199 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.6.25\" GEOIP_COUNTRY_CODE=NL | ASN: Global Layer B.V. | Country: NL
show less
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 12:36:10
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:36:05.736010 2026] [security2:error] [pid 19058:tid 19058] [client 213.152.187.243:59470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hollyndlaw.com"] [uri "/wp-config.php.old"] [unique_id "aomXtQ6EPs8yYH4oEbDG-gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 09:16:48
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:16:41.836758 2026] [security2:error] [pid 31559:tid 31559] [client 213.152.187.243:56698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.femalegamblers.org"] [uri "/.wp-config.php.swp"] [unique_id "aolo-fz6dIAutyGugX32_AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-08-22 08:00:35
(23 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110 ...
show more
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-22 07:57:35
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:57:30.314787 2026] [security2:error] [pid 32102:tid 32102] [client 213.152.187.243:58030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eileensharaga.com"] [uri "/wp-config.php_orig"] [unique_id "aolWamSAdC_C1P4sdAkIjAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Petros Stefanakis
2026-08-22 05:40:36
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 213.152.187.243 (connected-by.global-la ...
show more
(mod_security) mod_security triggered on hostname [redacted] 213.152.187.243 (connected-by.global-layer.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-22 03:32:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.187.243 (connected-by.global-layer.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 23:32:00.564637 2026] [security2:error] [pid 5190:tid 5190] [client 213.152.187.243:36310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.calogerolawfirm.com"] [uri "/wp-config.php.inc"] [unique_id "aokYMMP9Tc1_JT_US1dh3wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack