🇺🇸
TPI-Abuse
2026-09-07 23:01:34
(51 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:01:27.441145 2026] [security2:error] [pid 19774:tid 19774] [client 2a01:4f9:c015:804d::1:49154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "recipes.mikeneame.com"] [uri "/wp-config.php.bak"] [unique_id "ap9CR72o_aBY0a4qesiCvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 22:38:51
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:38:45.776368 2026] [security2:error] [pid 29678:tid 29678] [client 2a01:4f9:c015:804d::1:51696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tttns.com"] [uri "/about-jason//wp-config.php.bak"] [unique_id "ap889ecD60oxwuptqyX7GQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:42:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:42:40.011451 2026] [security2:error] [pid 19367:tid 19367] [client 2a01:4f9:c015:804d::1:60768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lahamradio.com"] [uri "/wp-config.php.bak"] [unique_id "ap8v0F2xmr6sXZwKlGVs3QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-07 21:26:11
(2 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:20:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:20:37.301015 2026] [security2:error] [pid 10218:tid 10218] [client 2a01:4f9:c015:804d::1:48118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puckerbottombikinis.com"] [uri "/wp-config.php.bak"] [unique_id "ap8qpbgDK7S0SoHBKYHQgAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:48:25
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:48:20.661343 2026] [security2:error] [pid 4296:tid 4296] [client 2a01:4f9:c015:804d::1:46578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pcga.golf"] [uri "/wp-config.php.bak"] [unique_id "ap8jFPO8HzWGqkpyPeiOcgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
arnisolutions
2026-09-07 18:55:27
(4 hours ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-07 and 2026-09-07 (UTC). Sample request: GET /backup.tar.gz HTTP/2.0
show less
Web App Attack
Hacking
🇩🇪
BlueWire Hosting
2026-09-07 17:13:01
(6 hours ago)
Probing websites for vulnerabilities
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-07 14:30:31
(9 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
🇵🇱
strefapi_com
2026-09-07 13:29:24
(10 hours ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇩🇪
jbcrn
2026-09-07 12:50:27
(11 hours ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:42:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:42:27.616123 2026] [security2:error] [pid 2704:tid 2704] [client 2a01:4f9:c015:804d::1:33492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pleaseaddbacon.com"] [uri "/wp-config.php.bak"] [unique_id "ap6xM0tYnAfwLn2_nCIyKgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 11:28:04
(12 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:14:16
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c015:804d::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:14:07.593197 2026] [security2:error] [pid 8204:tid 8204] [client 2a01:4f9:c015:804d::1:56876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oruhu.org"] [uri "/wp-config.php.bak"] [unique_id "ap6Ob0huuptCtabKgvByjAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇹
NotACaptcha
2026-09-07 09:18:22
(14 hours ago)
webserver:80 [07/Sep/2026] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings H ...
show more
webserver:80 [07/Sep/2026] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
webserver:443 [07/Sep/2026] "GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1" 404 5509 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
webserver:443 [07/Sep/2026] "GET /index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 5323 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
webserver:443 [07/Sep/2026] "GET /?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 200 5557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack