🇺🇸
TPI-Abuse
2026-09-15 00:35:41
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 20:35:33.350560 2026] [security2:error] [pid 27072:tid 27072] [client 2a01:4f8:1c1e:c125::1:43214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fgrotary.org"] [uri "/wp-config.php.bak"] [unique_id "aqiS1Ws6ySrTwxgyfTrUJAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-14 21:59:12
(20 hours ago)
Auto-ban: 209 malicious requests on 2026-09-13 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 209 malicious requests on 2026-09-13 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
🇳🇱
BlueWire Hosting
2026-09-14 18:24:55
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
🇳🇱
Site.eu
2026-09-14 18:16:44
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-14 16:07:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 12:07:45.084480 2026] [security2:error] [pid 13645:tid 13645] [client 2a01:4f8:1c1e:c125::1:49508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grannyswash.kunzteam.com"] [uri "/wp-config.php.bak"] [unique_id "aqgb0fLXuiDRAEgAcXVRLwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 14:10:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 10:10:12.184827 2026] [security2:error] [pid 23430:tid 23430] [client 2a01:4f8:1c1e:c125::1:52668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "losbarbarosdelnorte.com"] [uri "/wp-config.php.bak"] [unique_id "aqgARM7_MXv1XBtwrOzN5gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 10:34:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 06:33:58.539786 2026] [security2:error] [pid 27054:tid 27054] [client 2a01:4f8:1c1e:c125::1:59276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.guitarwisdom.benshermanguitar.com"] [uri "/wp-config.php.bak"] [unique_id "aqfNlvuwExfXB0tnA6eLewAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 07:23:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 03:23:46.298403 2026] [security2:error] [pid 29147:tid 29147] [client 2a01:4f8:1c1e:c125::1:35608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgtek.com"] [uri "/wp-config.php.bak"] [unique_id "aqehArBk4yIYfRHHPN42JAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 06:45:18
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 06:29:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:29:32.792875 2026] [security2:error] [pid 15403:tid 15420] [client 2a01:4f8:1c1e:c125::1:38504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tkfay.com"] [uri "/wp-config.php.bak"] [unique_id "aqeUTAqULHpyyOf1w1fQcgAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 05:19:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 01:19:31.603496 2026] [security2:error] [pid 15781:tid 15781] [client 2a01:4f8:1c1e:c125::1:48340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prostar.industries"] [uri "/wp-config.php.bak"] [unique_id "aqeD45QwcRrIMn3rHza9YwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
ScamAware
2026-09-14 03:23:07
(1 day ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot / scanner behavior). Hits from same IP in last 60 minutes: 2. Unique request paths counted internally: 1. Cloudflare action: managed_challenge. Cloudflare source: botFight.
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-14 03:09:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c1e:c125::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 23:09:28.274757 2026] [security2:error] [pid 15955:tid 15955] [client 2a01:4f8:1c1e:c125::1:49120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tttns.com"] [uri "/about-jason//wp-config.php.bak"] [unique_id "aqdlaGuXXRjropKeWHs9ewAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-14 02:52:39
(1 day ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a01:4f8:1c1e:c125::1 - - [14/Sep/2026:04:52:39 +0200] "GET /wp-config.php.bak HTTP/1.1" 302 7402 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-14 02:45:38
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking