🇺🇸
TPI-Abuse
2026-09-08 13:20:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:20:16.316655 2026] [security2:error] [pid 17919:tid 17919] [client 2400:d321:2301:9872::1:55244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kporterdesign.com"] [uri "/wp-config.php.bak"] [unique_id "aqALkGw_YHtkSvbt_okzeAAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
HostingGroup
2026-09-08 12:41:54
(2 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 9. First blocked: 2026-09-08.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:25:39
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:25:35.283270 2026] [security2:error] [pid 22472:tid 22472] [client 2400:d321:2301:9872::1:37782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cayman-islands-real-estate.com"] [uri "/wp-config.php.bak"] [unique_id "ap_-v9ZoeU_rOx955RZ8PwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:02:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:02:35.669345 2026] [security2:error] [pid 10091:tid 10091] [client 2400:d321:2301:9872::1:54530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coretherapyassoc.com.praemiumtech.com"] [uri "/wp-config.php.bak"] [unique_id "ap_5W-2a8BNv08zuFyVcfAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-08 11:45:26
(3 hours ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:32:55
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:32:50.561861 2026] [security2:error] [pid 6021:tid 6021] [client 2400:d321:2301:9872::1:49816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jennyfiore.com"] [uri "/wp-config.php.bak"] [unique_id "ap_yYqfyodSoYFNiWr3zFgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
soc-yk
2026-09-08 11:18:16
(4 hours ago)
Type: suspicious_network_activity
Risk: 100
Events: 286
Evidence:
- Persistent suspicious network a ...
show more
Type: suspicious_network_activity
Risk: 100
Events: 286
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Multi-event operational persistence identified
- Threat escalation behavior observed
show less
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-08 11:12:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:12:29.348114 2026] [security2:error] [pid 845:tid 845] [client 2400:d321:2301:9872::1:35866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.ontrek.com"] [uri "/wp-config.php.bak"] [unique_id "ap_tnVJH1-vKYAQGWf0OTQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:38:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:38:25.602933 2026] [security2:error] [pid 793:tid 793] [client 2400:d321:2301:9872::1:51744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fgrotary.org"] [uri "/wp-config.php.bak"] [unique_id "ap_loTC02zfh2Rb82LwjWAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:16:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:16:19.531771 2026] [security2:error] [pid 2233:tid 2233] [client 2400:d321:2301:9872::1:35882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "susanleeward.com"] [uri "/wp-config.php.bak"] [unique_id "ap_gc3Apur0mXJdCVd-WVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 10:01:34
(5 hours ago)
Fail2Ban triggered
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:58:57
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:58:53.082454 2026] [security2:error] [pid 24580:tid 24580] [client 2400:d321:2301:9872::1:45172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hydrometal-js.com"] [uri "/wp-config.php.bak"] [unique_id "ap_APQ_dxyrIJGE14XrLOgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:27:44
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:27:36.347417 2026] [security2:error] [pid 30767:tid 30769] [client 2400:d321:2301:9872::1:52064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vinylnotespodcast.com"] [uri "/wp-config.php.bak"] [unique_id "ap-q2IMiixczI30l3mTmcAAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-09-08 02:49:39
(12 hours ago)
Triggered Cloudflare WAF (firewallCustom) from IN.
Action taken: BLOCK
ASN: 141995 (Contabo Asia Pri ...
show more
Triggered Cloudflare WAF (firewallCustom) from IN.
Action taken: BLOCK
ASN: 141995 (Contabo Asia Private Limited)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-08T01:01:24Z
Ray ID: a37a0595a99f90f3
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 17:06:50
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:d321:2301:9872::1 (vmi3019872.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:06:45.927116 2026] [security2:error] [pid 14274:tid 14274] [client 2400:d321:2301:9872::1:45346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shhcenter.com"] [uri "/wp-config.php.bak"] [unique_id "ap7vJQY3ng0QUB9G4bzTWAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack