๐บ๐ธ
TPI-Abuse
2026-10-09 05:40:43
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:40:37.156587 2026] [security2:error] [pid 6914:tid 6914] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:11561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeanniemorrislaw.com"] [uri "/wp-config.php.save"] [unique_id "ash-VVrcdzG8eCmVpajVvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-09 04:50:09
(14 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-09 04:22:59
(14 hours ago)
2400:cb00:21:1000:efec:5333:2df:b7ed - - [09/Oct/2026:06:22:50 +0200] "GET /wp-config.php.old HTTP/1 ...
show more
2400:cb00:21:1000:efec:5333:2df:b7ed - - [09/Oct/2026:06:22:50 +0200] "GET /wp-config.php.old HTTP/1.1" 301 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
2400:cb00:21:1000:efec:5333:2df:b7ed - - [09/Oct/2026:06:22:48 +0200] "GET /.env HTTP/1.1" 301 565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
2400:cb00:21:1000:efec:5333:2df:b7ed - - [09/Oct/2026:06:22:49 +0200] "GET /wp-config.php HTTP/1.1" 301 583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 15:26:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 11:26:33.047326 2026] [security2:error] [pid 29205:tid 29205] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:11564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.midway-island.com"] [uri "/.env.dev"] [unique_id "ase2KYLDvx-WUeVpTT8IiQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 12:54:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 08:54:32.796014 2026] [security2:error] [pid 30015:tid 30020] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:10692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellmantitle.com"] [uri "/.env.bak"] [unique_id "aseSiJnYn_lW2PYMC4R4twAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-08 11:40:41
(1 day ago)
[ThuOct0813:40:36.7704722026][security2:error][pid2307337:tid2307443][client2400:cb00:21:1000:efec:5 ...
show more
[ThuOct0813:40:36.7704722026][security2:error][pid2307337:tid2307443][client2400:cb00:21:1000:efec:5333:2df:b7ed:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"[a-z0-9]~\$\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1158\"][id\"390581\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-DataLeakage-attempttoaccessbackupfile\(disablethisruleifyourequireaccesstofilesthatendwithatilde\)\"][severity\"CRITICAL\"][hostname\"feldenkraisticino.ch\"][uri\"/index.php~\"][unique_id\"aseBNNMrMXy3PV-FTHcjQQAAAcs\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 11:11:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:11:45.315494 2026] [security2:error] [pid 3906:tid 3921] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:12214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accutar.com"] [uri "/.env.dev"] [unique_id "asd6cTPM6b7xceXMjQWnqgAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:59:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:59:01.661355 2026] [security2:error] [pid 2665:tid 2665] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:11401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primemanagementmn.com"] [uri "/.env.save"] [unique_id "asaylWOELn-F8huktBtJxAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 17:36:48
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 13:36:43.171186 2026] [security2:error] [pid 16172:tid 16172] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:12377] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||intersystems-aircargo.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intersystems-aircargo.com"] [uri "/index.php.bak"] [unique_id "asaDK1rTUgEs6YsNqvrgGAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:34:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:34:14.691932 2026] [security2:error] [pid 11530:tid 11591] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:12022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/.env.local"] [unique_id "asXZ1p7mEtULeMzDTMAkZwAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:50:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:50:06.623836 2026] [security2:error] [pid 13832:tid 13832] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:11275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pronio.com"] [uri "/wp-config.php"] [unique_id "asVe_sP13pR32iYgOyOu0gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:07:58
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:07:51.252212 2026] [security2:error] [pid 2277:tid 2277] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:10527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessiedavison.com"] [uri "/.svn/entries"] [unique_id "asUOx0fKEDkYsjlim9nm5AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:36:12
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:36:05.798985 2026] [security2:error] [pid 428:tid 428] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:10191] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||psychiatryabuse.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "psychiatryabuse.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asTBBeHWjV-9Nci6P_wZjgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:40:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:40:26.644302 2026] [security2:error] [pid 15612:tid 15612] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:11061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtrl.com"] [uri "/.env.local"] [unique_id "asSl6pHn9yz18BczrLiT7wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 03:44:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:21:1000:efec:5333:2df:b7ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:44:48.803585 2026] [security2:error] [pid 6575:tid 6575] [client 2400:cb00:21:1000:efec:5333:2df:b7ed:13285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rangerroma.com"] [uri "/.env.staging"] [unique_id "asRusD0IhDh38pnXb-gC7wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack