๐บ๐ธ
TPI-Abuse
2026-09-22 18:44:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:44:50.612497 2026] [security2:error] [pid 25267:tid 25267] [client 217.219.68.46:40310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pointandshootfilm.com"] [uri "/wp-config.php.bak"] [unique_id "arLMolI5drRYgDoWFwZvvgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:54:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:54:28.549623 2026] [security2:error] [pid 27806:tid 27806] [client 217.219.68.46:49576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theledman.com"] [uri "/wp-config.php.bak"] [unique_id "arKyxK4hDFkBLc6lbLUCgwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 03:35:42
(2 days ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env | 2026-09-22 03:35 UTC
show less
Hacking
Web App Attack
๐ฌ๐ง
[email protected]
2025-08-04 21:47:46
(1 year ago)
www.polaris-learning-plus.com:80 217.219.68.46 - - [04/Aug/2025:21:47:44 +0000] "HEAD //Archive.zip ...
show more
www.polaris-learning-plus.com:80 217.219.68.46 - - [04/Aug/2025:21:47:44 +0000] "HEAD //Archive.zip HTTP/1.1" 404 205 "-" "-"
www.polaris-learning-plus.com:80 217.219.68.46 - - [04/Aug/2025:21:47:45 +0000] "HEAD //polaris-learning-plus.zip HTTP/1.1" 404 205 "-" "-"
www.polaris-learning-plus.com:80 217.219.68.46 - - [04/Aug/2025:21:47:45 +0000] "HEAD //polaris-learning-plus.com.zip HTTP/1.1" 404 205 "-" "-"
...
show less
Web App Attack
๐ณ๐ฟ
Tripwire
2025-07-31 15:42:14
(1 year ago)
Scanning for backup files - /Backup.zip
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-16 16:47:31
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 16 12:47:21.329071 2025] [security2:error] [pid 28715:tid 28715] [client 217.219.68.46:42168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seoanalyticslocal.com"] [uri "/wp-config.php.old"] [unique_id "aHfXmb4MuKYwqZMaTE5B6wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-15 15:40:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐ฎ๐น
VHosting
2025-07-15 03:00:07
(1 year ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-11 18:59:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 11 14:58:59.216136 2025] [security2:error] [pid 6244:tid 6244] [client 217.219.68.46:47924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thesiteworks.com"] [uri "/wp-config.php1"] [unique_id "aHFe841YokgwSXuH2klT2AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-07-06 05:40:50
(1 year ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-06 05:27:11
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 06 01:27:04.138423 2025] [security2:error] [pid 15553:tid 15553] [client 217.219.68.46:46120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chicagochristmascards.com"] [uri "/wp-config.php.save"] [unique_id "aGoJKB5Nh3OLfrErXHypjAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-22 14:58:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐ซ๐ท
pm33
2025-05-10 13:23:48
(1 year ago)
Wordpress login attempts
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-05-09 22:26:10
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 09 18:26:03.203082 2025] [security2:error] [pid 349720:tid 349720] [client 217.219.68.46:37788] [client 217.219.68.46] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galaxyretro.com"] [uri "/wp-config.php~"] [unique_id "aB6A-4QjsV76Uy2Q0pDZwwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-09 19:39:51
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 217.219.68.46 (srv01.ibgserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 09 15:39:46.120891 2025] [security2:error] [pid 3451666:tid 3451666] [client 217.219.68.46:46118] [client 217.219.68.46] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chiggerland.com"] [uri "/wp-config.php.bak"] [unique_id "aB5aApn1IpxVftzazJ5dyAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack