๐ฉ๐ช
Jarda_H
2026-09-04 00:53:33
(20 minutes ago)
php-url-scan Attack Detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 23:36:53
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 2607:f298:5:114b::e7f:e9ff (sub1.eregression.sh ...
show more
(mod_security) mod_security (id:949110) triggered by 2607:f298:5:114b::e7f:e9ff (sub1.eregression.shop): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:36:50.637030 2026] [security2:error] [pid 32662:tid 32662] [client 2607:f298:5:114b::e7f:e9ff:59740] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ugandaconnection.com"] [uri "/wp-config.php.bak"] [unique_id "apoEku-rc3xTml5kIyRIjAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-03 22:42:35
(2 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 22:23:08
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::e7f:e9ff (sub1.eregression.sh ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::e7f:e9ff (sub1.eregression.shop): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:23:01.506535 2026] [security2:error] [pid 28752:tid 28752] [client 2607:f298:5:114b::e7f:e9ff:36914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boat-registration-france.com"] [uri "/.env.save"] [unique_id "apnzRWmhCndNNeIwyUUvLwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-03 20:48:14
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-03 20:38:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::e7f:e9ff (sub1.eregression.sh ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::e7f:e9ff (sub1.eregression.shop): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:38:34.348697 2026] [security2:error] [pid 18291:tid 18322] [client 2607:f298:5:114b::e7f:e9ff:33114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tsdlivesearch.com"] [uri "/wp-config.php.bak"] [unique_id "apnaypxhn2CvdyQusQV2hAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-09-03 20:26:32
(4 hours ago)
[Thu Sep 03 14:26:31.204190 2026] [authz_core:error] [pid 169069:tid 140669096027712] [client 2607:f ...
show more
[Thu Sep 03 14:26:31.204190 2026] [authz_core:error] [pid 169069:tid 140669096027712] [client 2607:f298:5:114b::e7f:e9ff:47828] AH01630: client denied by server configuration: /var/www/horde/.env.swp
[Thu Sep 03 14:26:31.310669 2026] [authz_core:error] [pid 169069:tid 140668089394752] [client 2607:f298:5:114b::e7f:e9ff:47828] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.bak
[Thu Sep 03 14:26:31.335188 2026] [authz_core:error] [pid 169069:tid 140668466869824] [client 2607:f298:5:114b::e7f:e9ff:47828] AH01630: client denied by server configuration: /var/www/horde/.env.bak
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-03 20:10:10
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::e7f:e9ff (sub1.eregression.sh ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::e7f:e9ff (sub1.eregression.shop): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:10:05.076151 2026] [security2:error] [pid 19106:tid 19106] [client 2607:f298:5:114b::e7f:e9ff:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perl-photo.com"] [uri "/.env"] [unique_id "apnUHSiDth_qYtXBFrL6sAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-03 19:21:56
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ฐ
HostingGroup
2026-09-03 19:01:54
(6 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 4. First blocked: 2026-09-03.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-03 18:50:15
(6 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-03 18:48:54
(6 hours ago)
2607:f298:5:114b::e7f:e9ff - - [03/Sep/2026:20:48:51 +0200] "GET /wp-config.php.orig HTTP/1.1" 404 4 ...
show more
2607:f298:5:114b::e7f:e9ff - - [03/Sep/2026:20:48:51 +0200] "GET /wp-config.php.orig HTTP/1.1" 404 453 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:114b::e7f:e9ff - - [03/Sep/2026:20:48:51 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4419 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:114b::e7f:e9ff - - [03/Sep/2026:20:48:51 +0200] "GET /wp-config.php.save HTTP/1.1" 404 4418 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:114b::e7f:e9ff - - [03/Sep/2026:20:48:51 +0200] "GET /wp-config.php.txt HTTP/1.1" 404 4417 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:114b::e7f:e9ff - - [03/Sep/2026:20:48:51 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4417 "-" "Mozilla/5.
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-03 18:42:19
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::e7f:e9ff (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::e7f:e9ff (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:42:14.505226 2026] [security2:error] [pid 1591161:tid 1591178] [client 2607:f298:5:114b::e7f:e9ff:51484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.robotics4fun.com"] [uri "/wp-config.php.save"] [unique_id "apm_hi9AW-EQ-tMLAGvUQwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-09-03 18:00:12
(7 hours ago)
WordPress content enumeration
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-03 17:20:21
(7 hours ago)
Excessive 404/403 errors
Brute-Force