๐บ๐ธ
TPI-Abuse
2026-09-03 08:04:02
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 04:03:55.331186 2026] [security2:error] [pid 11388:tid 11388] [client 2607:f298:5:117b::31e:fbe3:50992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fxztrader.com"] [uri "/wp-config.php.orig"] [unique_id "apkp678sSjuadHHWwq8kOgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-03 07:01:16
(12 hours ago)
2607:f298:5:117b::31e:fbe3 - - [03/Sep/2026:17:01:15 +1000] "GET /pathscan-30d5b58826eb-nope.env HTT ...
show more
2607:f298:5:117b::31e:fbe3 - - [03/Sep/2026:17:01:15 +1000] "GET /pathscan-30d5b58826eb-nope.env HTTP/1.1" 404 997 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:117b::31e:fbe3 - - [03/Sep/2026:17:01:16 +1000] "GET /.hg/store/00manifest.i HTTP/1.1" 404 997 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:117b::31e:fbe3 - - [03/Sep/2026:17:01:16 +1000] "GET /wp-config.php.txt HTTP/1.1" 404 997 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:117b::31e:fbe3 - - [03/Sep/2026:17:01:16 +1000] "GET /.git/HEAD HTTP/1.1" 404 997 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:117b::31e:fbe3 - - [03/Sep/2026:17:01:16 +1000] "GET /.env.dev HTTP/1.1" 404 997 "-" "Mozilla/5.0
...
show less
Bad Web Bot
๐ซ๐ฎ
YF
2026-09-03 07:00:37
(12 hours ago)
WordPress content enumeration
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-09-03 02:28:29
(17 hours ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -55.819 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -55.819 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Sa
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-02 18:17:22
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-02 17:21:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:20:56.608894 2026] [security2:error] [pid 16579:tid 16579] [client 2607:f298:5:117b::31e:fbe3:37420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bamedica.com"] [uri "/wp-config.php.bak"] [unique_id "apha-D5W_kKanDO79i84EQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-02 17:13:23
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /wp-json/batch/v1 | 2026-09-02 17:13 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 16:55:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 12:55:07.631968 2026] [security2:error] [pid 22948:tid 22948] [client 2607:f298:5:117b::31e:fbe3:52008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tourissue.com"] [uri "/wp-config.php.bak"] [unique_id "aphU65hWjaKOeOrteO4KhgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 16:39:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 12:39:39.978308 2026] [security2:error] [pid 8702:tid 8702] [client 2607:f298:5:117b::31e:fbe3:45046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modalguitarist.com"] [uri "/wp-config.php.bak"] [unique_id "aphRS4_KZmplb-84XDjJ7AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 16:08:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 12:08:52.267795 2026] [security2:error] [pid 16623:tid 16623] [client 2607:f298:5:117b::31e:fbe3:39322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lesdaniels.com"] [uri "/wp-config.php.bak"] [unique_id "aphKFIw0cHq70hJvXwPewgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 15:02:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:02:27.426445 2026] [security2:error] [pid 5198:tid 5198] [client 2607:f298:5:117b::31e:fbe3:45090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indyham.com"] [uri "/wp-config.php.bak"] [unique_id "apg6g-5Fwke5bonYdkmzygAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-02 14:06:57
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 2607:f298:5:117b::31e:fbe3 (US/United S ...
show more
(mod_security) mod_security triggered on hostname [redacted] 2607:f298:5:117b::31e:fbe3 (US/United States/ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-02 13:32:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:32:29.220328 2026] [security2:error] [pid 12742:tid 12742] [client 2607:f298:5:117b::31e:fbe3:53196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tttns.com"] [uri "/about-jason//wp-config.php.bak"] [unique_id "apglbTNkCKroUCu3gT84LAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 13:09:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:09:30.678294 2026] [security2:error] [pid 25443:tid 25443] [client 2607:f298:5:117b::31e:fbe3:37250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pcga.golf"] [uri "/wp-config.php.bak"] [unique_id "apggCmim9Y0yf2McG052KAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:28:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::31e:fbe3 (ip-2607-F298-0005-117B-0000-0000-031E-FBE3.dreamhost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:28:49.129100 2026] [security2:error] [pid 4179092:tid 4179181] [client 2607:f298:5:117b::31e:fbe3:35806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "visionforandfromchildren.org"] [uri "/wp-config.php.bak"] [unique_id "apgWgcyJvhXPas5_p_H3zQAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack