🇺🇸
TPI-Abuse
2026-09-06 21:39:07
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:39:00.435618 2026] [security2:error] [pid 8767:tid 8767] [client 2607:f298:5:117b::8cf:9d13:38060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.godcanuseyou.com"] [uri "/wp-config.php.bak"] [unique_id "ap3ddG7BPy2nOgIfvtETYwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:38:16
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:38:08.164956 2026] [security2:error] [pid 12642:tid 12776] [client 2607:f298:5:117b::8cf:9d13:51610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.councilofforeignministers.aafm.us"] [uri "/wp-config.php.bak"] [unique_id "ap3PMOXyLOKny1WIAYlEwAAAAoQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:13:49
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:13:44.188884 2026] [security2:error] [pid 2948:tid 2948] [client 2607:f298:5:117b::8cf:9d13:36830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modalguitarist.com"] [uri "/wp-config.php~"] [unique_id "ap3JeL1JmRdtOjcJO1RfjwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:46:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:46:45.493909 2026] [security2:error] [pid 18999:tid 18999] [client 2607:f298:5:117b::8cf:9d13:51362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.kbalan.com"] [uri "/wp-config.php.bak"] [unique_id "ap2nBdjaCDc-PvPel4S8nQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:29:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:28:56.792967 2026] [security2:error] [pid 13894:tid 13894] [client 2607:f298:5:117b::8cf:9d13:34718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brazilianbottom.com"] [uri "/wp-config.php.bak"] [unique_id "ap2i2I4vGu9qGfan72QpCwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:59:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:59:10.976312 2026] [security2:error] [pid 20309:tid 20309] [client 2607:f298:5:117b::8cf:9d13:34358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crittergetterpestcontrol.azcrittergetter.com"] [uri "/wp-config.php.bak"] [unique_id "ap2NzrJinzDRUnwQipOuqAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:06:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:06:35.845495 2026] [security2:error] [pid 29995:tid 29995] [client 2607:f298:5:117b::8cf:9d13:36950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.art.mavikalem.org"] [uri "/wp-config.php.bak"] [unique_id "ap2Be_LdTgJlYIH8m_PVZQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:17:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:17:10.150185 2026] [security2:error] [pid 25157:tid 25157] [client 2607:f298:5:117b::8cf:9d13:52354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ink2wear.com"] [uri "/wp-config.php.bak"] [unique_id "ap1ZxtzWdYA_Z55AAyS4xQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 08:57:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 04:57:28.986256 2026] [security2:error] [pid 3535:tid 3535] [client 2607:f298:5:117b::8cf:9d13:44298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grannyswash.kunzteam.com"] [uri "/wp-config.php.bak"] [unique_id "ap0q-E4curTHyn6X7v9WVwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-06 08:32:48
(1 day ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack
🇧🇪
cmbplf
2026-09-06 08:24:36
(1 day ago)
304 requests with url.path *.php.bak
288 requests with url.path */debug.log
288 requests with url ...
show more
304 requests with url.path *.php.bak
288 requests with url.path */debug.log
288 requests with url.path *debug.log
213 requests with url.path *.git/*
105 requests with url.path *.sql.gz
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 08:14:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 04:14:31.369684 2026] [security2:error] [pid 21756:tid 21756] [client 2607:f298:5:117b::8cf:9d13:42034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pixelspective.com"] [uri "/wp-config.php~"] [unique_id "ap0g55UjUMR0BYHOFwcjlwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 07:58:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 03:58:39.026336 2026] [security2:error] [pid 29089:tid 29089] [client 2607:f298:5:117b::8cf:9d13:39658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gerrytolentino.net"] [uri "/wp-config.php.bak"] [unique_id "ap0dL-BDMGM_zxLgW1A3gAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 07:50:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 07:38:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:117b::8cf:9d13 (hauteintl.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 03:38:25.661062 2026] [security2:error] [pid 6423:tid 6423] [client 2607:f298:5:117b::8cf:9d13:49852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bamedica.com"] [uri "/wp-config.php.bak"] [unique_id "ap0YcfeQQoRiFvJikl_gRAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack