4server
2025-05-11 23:51:32
(3 days ago)
[MonMay1201:51:25.5196442025][security2:error][pid107534:tid107564][client2607:f1c0:5ff:5f:74:208:56 ... show more [MonMay1201:51:25.5196442025][security2:error][pid107534:tid107564][client2607:f1c0:5ff:5f:74:208:56:106:0][client2607:f1c0:5ff:5f:74:208:56:106]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"wp-config\\\\\\\\.php\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/99_asl_jitp.conf\"][line\"3178\"][id\"381206\"][rev\"4\"][msg\"Atomicorp.comWAFRules-VirtualJustInTimePatch:AccesstoWordPressconfigurationfileblocked\"][data\"wp-config.php\"][severity\"CRITICAL\"][hostname\"server-privato.com\"][uri\"/wp-config.php.org\"][unique_id\"aCE3_V8G0fwf1BYwq_jMbgAAAQo\"] show less
Hacking
Web App Attack
TPI-Abuse
2025-05-09 19:50:24
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 09 15:50:21.309455 2025] [security2:error] [pid 3402353:tid 3402353] [client 2607:f1c0:5ff:5f:74:208:56:106:44362] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kamireddi.com"] [uri "/wp-config.php~"] [unique_id "aB5cfSIP5LPQa4yplsB02wAAABo"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-07 16:50:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 07 12:50:54.670132 2025] [security2:error] [pid 2133536:tid 2133536] [client 2607:f1c0:5ff:5f:74:208:56:106:55966] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "platinummedicalevaluations.com"] [uri "/wp-config.php.bak"] [unique_id "aBuPbqJ10PqIcNMAPPHnvgAAABM"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-05 14:27:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 10:27:06.618009 2025] [security2:error] [pid 1099598:tid 1099598] [client 2607:f1c0:5ff:5f:74:208:56:106:49494] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deckmasterscompany.com"] [uri "/wp-config.php_bak"] [unique_id "aBjKuty_hIL_NNi7oyMOcwAAABU"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-02 14:54:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 02 10:54:19.253895 2025] [security2:error] [pid 2581854:tid 2581854] [client 2607:f1c0:5ff:5f:74:208:56:106:51460] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teatrosohoclub.com"] [uri "/wp-config.php~"] [unique_id "aBTcm0EkqoptOLiw8YFSzAAAABM"] show less
Brute-Force
Bad Web Bot
Web App Attack
4server
2025-05-01 21:44:39
(1 week ago)
[ThuMay0123:44:34.0018652025][security2:error][pid2693023:tid2693129][client2607:f1c0:5ff:5f:74:208: ... show more [ThuMay0123:44:34.0018652025][security2:error][pid2693023:tid2693129][client2607:f1c0:5ff:5f:74:208:56:106:0][client2607:f1c0:5ff:5f:74:208:56:106]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"wp-config\\\\\\\\.php\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/99_asl_jitp.conf\"][line\"3178\"][id\"381206\"][rev\"4\"][msg\"Atomicorp.comWAFRules-VirtualJustInTimePatch:AccesstoWordPressconfigurationfileblocked\"][data\"wp-config.php\"][severity\"CRITICAL\"][hostname\"giuseppeasaro.com\"][uri\"/wp-config.php.org\"][unique_id\"aBPrQXIvn8wEXsy_j8GOggAAAVg\"] show less
Port Scan
Brute-Force
Web App Attack
TPI-Abuse
2025-04-30 07:13:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 03:12:58.354611 2025] [security2:error] [pid 10584:tid 10584] [client 2607:f1c0:5ff:5f:74:208:56:106:52142] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulshorrock.com"] [uri "/wp-config.php1"] [unique_id "aBHNets-iPO3SeX2nVB2bQAAAAA"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-29 11:14:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 07:14:39.471406 2025] [security2:error] [pid 31368:tid 31478] [client 2607:f1c0:5ff:5f:74:208:56:106:33190] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelmercier.com"] [uri "/wp-config.phpold"] [unique_id "aBC0n-mjSdH_EC-vCwd2IgAAAIE"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-29 08:15:38
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 04:15:34.365436 2025] [security2:error] [pid 30930:tid 30930] [client 2607:f1c0:5ff:5f:74:208:56:106:42554] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livresanciens.fritsknuf.com"] [uri "/wp-config.php1"] [unique_id "aBCKpoTw3ru82_BndTZnzQAAAAg"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-28 21:11:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 28 17:11:32.683900 2025] [security2:error] [pid 1752758:tid 1752758] [client 2607:f1c0:5ff:5f:74:208:56:106:58266] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cosplayculture.com"] [uri "/wp-config.php.orig"] [unique_id "aA_vBABFe36ek30PDhavDQAAAAc"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-27 19:50:36
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 27 15:50:29.265992 2025] [security2:error] [pid 28177:tid 28177] [client 2607:f1c0:5ff:5f:74:208:56:106:34480] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kiddocommunication.com"] [uri "/wp-config.php.save"] [unique_id "aA6KhY6OgtSGV2MG3soPdgAAAAY"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-27 10:17:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 27 06:17:18.263695 2025] [security2:error] [pid 363793:tid 363793] [client 2607:f1c0:5ff:5f:74:208:56:106:43452] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soonerstone.com"] [uri "/wp-config.php.orig"] [unique_id "aA4ELlGdYKTrTv6sUVgtcQAAAAY"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-26 18:23:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 26 14:23:04.139062 2025] [security2:error] [pid 3087:tid 3087] [client 2607:f1c0:5ff:5f:74:208:56:106:34684] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waterspell.net"] [uri "/wp-config.php.bkp"] [unique_id "aA0kiPCu895jHS90n0gVhQAAAAg"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-25 17:29:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 13:29:18.966912 2025] [security2:error] [pid 1860890:tid 1860890] [client 2607:f1c0:5ff:5f:74:208:56:106:53354] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cherylpelletier.com"] [uri "/wp-config.bak"] [unique_id "aAvGbiuGaY4c3z0q_TiaqgAAAAs"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-25 16:02:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfo ... show more (mod_security) mod_security (id:210492) triggered by 2607:f1c0:5ff:5f:74:208:56:106 (infong892.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 12:02:03.657323 2025] [security2:error] [pid 28468:tid 28468] [client 2607:f1c0:5ff:5f:74:208:56:106:52092] [client 2607:f1c0:5ff:5f:74:208:56:106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infinite-fitness.com"] [uri "/wp-config.bak"] [unique_id "aAux-_i4tIc0VTSm4E33pwAAAA0"] show less
Brute-Force
Bad Web Bot
Web App Attack