๐บ๐ธ
TPI-Abuse
2026-08-24 00:18:26
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 20:18:16.742418 2026] [security2:error] [pid 25635:tid 25673] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:53374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.busybeerestaurant.com"] [uri "/wp-config.php.original"] [unique_id "aouNyIo8keoO3L2j-a8DJgAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 19:44:31
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 15:44:24.758669 2026] [security2:error] [pid 27633:tid 27633] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:45720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.abeltours.com"] [uri "/wp-config.php_orig"] [unique_id "aotNmB0De4sPyOP5h12rswAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-22 23:46:32
(1 month ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
hchristo
2026-08-22 20:14:22
(1 month ago)
[Sat Aug 22 22:13:52.591670 2026] [authz_core:error] [pid 63005:tid 63097] [client 2620:7:6001:5c2c: ...
show more
[Sat Aug 22 22:13:52.591670 2026] [authz_core:error] [pid 63005:tid 63097] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:59442] AH01630: client denied by server configuration: /var/www/kd1007/htdocs/nin-kin.de/.wp-config.php.swp
[Sat Aug 22 22:14:21.944808 2026] [authz_core:error] [pid 63005:tid 63082] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:48618] AH01630: client denied by server configuration: /var/www/kd1007/htdocs/nin-kin.de/.env.bak
[Sat Aug 22 22:14:21.947970 2026] [authz_core:error] [pid 63005:tid 63088] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:48624] AH01630: client denied by server configuration: /var/www/kd1007/htdocs/nin-kin.de/.env~
[Sat Aug 22 22:14:21.949023 2026] [authz_core:error] [pid 63005:tid 63059] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:48616] AH01630: client denied by server configuration: /var/www/kd1007/htdocs/nin-kin.de/env.bak
[Sat Aug 22 22:14:21.950980 2026] [authz_core:error] [pid 63005:tid 63066] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:48
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-22 17:09:56
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:09:52.735396 2026] [security2:error] [pid 28964:tid 28964] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:48142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.luxandunion.com"] [uri "/wp-config.php.OLD"] [unique_id "aonX4HTwI7ylBFeLRbIyfAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 15:03:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:03:44.733532 2026] [security2:error] [pid 18929:tid 18929] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:48014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kildarafarms.com"] [uri "/.wp-config.php.swp"] [unique_id "aom6UOrg-bK_4lc7UVuQmAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-22 13:20:18
(1 month ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-22 10:12:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:12:03.742044 2026] [security2:error] [pid 15100:tid 15100] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:40140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.garanta.co"] [uri "/wp-config.php.BAK"] [unique_id "aol18zoRxxeYWfMEk2FqJAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 09:47:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:46:53.743046 2026] [security2:error] [pid 22196:tid 22196] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:51424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fredlandia.com"] [uri "/wp-config.php.SAVE"] [unique_id "aolwDRi0RliUOu50z1RNUQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 02:42:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 22:42:01.806982 2026] [security2:error] [pid 21841:tid 21841] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:44502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bostonlog.com"] [uri "/wp-config.php.BAK"] [unique_id "aokMeV1FcKrHcApaQrIqkQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-22 00:20:08
(1 month ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-21 23:12:18
(1 month ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 21:37:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001:5c2c:c834:1911:e2c3:60d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:37:43.733707 2026] [security2:error] [pid 27368:tid 27368] [client 2620:7:6001:5c2c:c834:1911:e2c3:60d2:57566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wmionline.org"] [uri "/wp-config.php.txt"] [unique_id "aojFJ45VtSKhyK19uVhvyQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SiyCah
2026-08-14 03:00:02
(1 month ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-14 01:07:34
(1 month ago)
Credential and secrets file probing | req: /wp-config.php.save | UA: Mozilla/5.0 (Macintosh; Intel M ...
show more
Credential and secrets file probing | req: /wp-config.php.save | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.4.19
show less
Hacking
Web App Attack