🇺🇸
TPI-Abuse
2026-09-10 01:52:22
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 21:52:14.101090 2026] [security2:error] [pid 13506:tid 13506] [client 217.71.237.129:49693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rcto.us"] [uri "/%23wp-config.php%23"] [unique_id "aqINTgAlGWfmJE58ycSUPQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 01:33:29
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 21:33:21.812025 2026] [security2:error] [pid 7154:tid 7154] [client 217.71.237.129:63664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oliverhardy.com"] [uri "/%23wp-config.php%23"] [unique_id "aqII4TmhJWlpvdSyM87r9wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-10 01:19:17
(12 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /%23wp-config.php%23 | 2026-09-10 01:19 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 01:11:26
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 21:11:22.953035 2026] [security2:error] [pid 26447:tid 26447] [client 217.71.237.129:50785] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sacoriverjazz.org"] [uri "/%23wp-config.php%23"] [unique_id "aqIDuodBfQkfsK4UKlAAYAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 00:43:40
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 20:43:35.385993 2026] [security2:error] [pid 20431:tid 20431] [client 217.71.237.129:58645] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knoxbestos.com"] [uri "/%23wp-config.php%23"] [unique_id "aqH9N2pkFjMSbWhE7_l36QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 00:16:42
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 20:16:35.549167 2026] [security2:error] [pid 26070:tid 26070] [client 217.71.237.129:56643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thehealthyplaceclayton.com"] [uri "/%23wp-config.php%23"] [unique_id "aqH246GHxARvHwUPL1V2VAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 22:30:15
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 18:30:10.974067 2026] [security2:error] [pid 11673:tid 11673] [client 217.71.237.129:58952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tradersworldmarket.com"] [uri "/%23wp-config.php%23"] [unique_id "aqHd8oCrKycJbKvJFw8ahwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 22:05:24
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 18:05:18.112303 2026] [security2:error] [pid 29611:tid 29625] [client 217.71.237.129:50928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.busybeerestaurant.com"] [uri "/%23wp-config.php%23"] [unique_id "aqHYHlCIwxOLgbZuZdVG1QAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 21:48:22
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.71.237.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 17:48:16.192527 2026] [security2:error] [pid 2106006:tid 2106006] [client 217.71.237.129:55232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ftiptondds.com"] [uri "/%23wp-config.php%23"] [unique_id "aqHUIBcWjs_AGoLsswRRfAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇰🇿
Sipilen
2026-04-26 10:14:00
(4 months ago)
Possible port scan detected in MikroTik firewall logs: connection-state:new proto UDP proto UDP len ...
show more
Possible port scan detected in MikroTik firewall logs: connection-state:new proto UDP proto UDP len 48. Total attempts in last 15m: 5
show less
Port Scan