🇳🇱
Alt255
2026-09-13 03:28:55
(7 minutes ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a01:4f9:c015:5baa::1 - - [13/Sep/2026:05:28:54 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 6342 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-13 01:41:36
(1 hour ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: registry.budyn.xyz | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-13 00:31:17
(3 hours ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a01:4f9:c015:5baa::1 - - [13/Sep/2026:02:31:16 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 6153 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:36:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:36:29.697763 2026] [security2:error] [pid 12773:tid 12773] [client 2a01:4f9:c015:5baa::1:38994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ismaelcavazos.com"] [uri "/wp-config.php.bak"] [unique_id "aqXT7WNJldmrFM946DdKkAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:16:32
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:16:26.748206 2026] [security2:error] [pid 22517:tid 22517] [client 2a01:4f9:c015:5baa::1:51294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modalguitarist.com"] [uri "/wp-config.php.bak"] [unique_id "aqXPOr3TVSje152r1YZZewAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-12 20:50:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 17:54:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 13:54:51.620338 2026] [security2:error] [pid 4019082:tid 4019082] [client 2a01:4f9:c015:5baa::1:39798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joevallone.com"] [uri "/wp-config.php.bak"] [unique_id "aqWR6-bhIiRL9sIF_t2gRgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 12:51:21
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:51:15.649608 2026] [security2:error] [pid 7206:tid 7206] [client 2a01:4f9:c015:5baa::1:36530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.femalegamblers.mobileonlinecasinos.co"] [uri "/wp-config.php.bak"] [unique_id "aqVKw3ivAyimnCzn8j2ckQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:55:45
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:55:37.566696 2026] [security2:error] [pid 5745:tid 5745] [client 2a01:4f9:c015:5baa::1:42436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mavikalem.org"] [uri "/wp-config.php.bak"] [unique_id "aqUTiT9Kw_J_P45puqD4jwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-12 05:58:40
(21 hours ago)
2a01:4f9:c015:5baa::1 - - [12/Sep/2026:07:58:40 +0200] "GET /.env HTTP/2.0" 404 63939 "-" "Mozilla/5 ...
show more
2a01:4f9:c015:5baa::1 - - [12/Sep/2026:07:58:40 +0200] "GET /.env HTTP/2.0" 404 63939 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 05:36:45
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:36:39.567565 2026] [security2:error] [pid 15076:tid 15076] [client 2a01:4f9:c015:5baa::1:40040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulshorrock.com"] [uri "/wp-config.php.bak"] [unique_id "aqTk5z75efvhXRNAjxi4KwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 01:30:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:30:15.121880 2026] [security2:error] [pid 5316:tid 5316] [client 2a01:4f9:c015:5baa::1:40000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeremyscraig.com"] [uri "/wp-config.php.bak"] [unique_id "aqSrJwh5U60J2Bhvwac1KgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
gumbysoft
2026-09-11 22:26:15
(1 day ago)
Unauthorized web vulnerability scan (/.env, wordpress, etc.)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:31:51
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:5baa::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:31:43.194558 2026] [security2:error] [pid 16628:tid 16628] [client 2a01:4f9:c015:5baa::1:37534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crittergetterpestcontrol.azcrittergetter.com"] [uri "/wp-config.php.bak"] [unique_id "aqAAL3v97RmsDEAIWJSKsAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
wielorzeczownik
2026-09-08 11:30:13
(4 days ago)
5 failed attempts
2026-09-08 13:29:52 GET /.env -> 404
2026-09-08 13:29:55 GET /.env.bak -> 404 ...
show more
5 failed attempts
2026-09-08 13:29:52 GET /.env -> 404
2026-09-08 13:29:55 GET /.env.bak -> 404
2026-09-08 13:29:58 GET /.env.old -> 404
2026-09-08 13:30:08 GET /.env.save -> 404
2026-09-08 13:30:12 GET /.env.swp -> 404
show less
Web App Attack
Hacking