🇺🇸
TPI-Abuse
2026-09-05 04:18:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 00:18:32.039417 2026] [security2:error] [pid 12471:tid 12471] [client 2a02:1778::113:25c:41116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.michaelthompson.biz"] [uri "/wp-config.php.bak"] [unique_id "apuYGOAeFj1x8e6mpSIgjAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 00:45:14
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:44:58.893462 2026] [security2:error] [pid 23477:tid 23477] [client 2a02:1778::113:25c:41536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.ontrek.com"] [uri "/wp-config.php.bak"] [unique_id "aptmCvaHkF5gtI_VQGuzMAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-04 22:46:44
(12 hours ago)
110 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 21:30:49
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:30:44.515156 2026] [security2:error] [pid 13067:tid 13067] [client 2a02:1778::113:25c:42328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.museum.henning.org"] [uri "/wp-config.php.bak"] [unique_id "aps4hCC5bygARx4B7BWivwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:53:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:53:14.546470 2026] [security2:error] [pid 5699:tid 5699] [client 2a02:1778::113:25c:35720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desdier.com"] [uri "/wp-config.php.bak"] [unique_id "apr3eiZbUbqFVwkY6YmXSQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-04 16:03:16
(18 hours ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 15:46:11
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
VanKoh
2026-09-04 12:21:23
(22 hours ago)
2a02:1778::113:25c - - [04/Sep/2026:06:21:20 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Moz ...
show more
2a02:1778::113:25c - - [04/Sep/2026:06:21:20 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:1778::113:25c - - [04/Sep/2026:06:21:21 -0600] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:1778::113:25c - - [04/Sep/2026:06:21:22 -0600] "GET /wp-config.php.save HTTP/1.1" 301 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Port Scan
Web App Attack
🇮🇹
VHosting
2026-09-04 04:05:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2024-09-25 01:44:18
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 24 21:44:13.879940 2024] [security2:error] [pid 2381736:tid 2381772] [client 2a02:1778::113:25c:46538] [client 2a02:1778::113:25c] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.pcfinancial.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.pcfinancial.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZvNq7Tv-pSspGEXZwMOZ9wAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-09-24 19:45:16
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 24 15:45:11.339931 2024] [security2:error] [pid 24084:tid 24111] [client 2a02:1778::113:25c:35316] [client 2a02:1778::113:25c] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||councilofforeignministers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "councilofforeignministers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZvMWxxeh1aQ5gXtCZzTCGAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-09-24 18:11:05
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 24 14:10:59.875979 2024] [security2:error] [pid 10162:tid 10162] [client 2a02:1778::113:25c:35748] [client 2a02:1778::113:25c] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hookedupfishing.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hookedupfishing.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ZvMAswRb_1nZE_vc9-MG0QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-09-24 17:33:52
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 24 13:33:44.892350 2024] [security2:error] [pid 289591:tid 289591] [client 2a02:1778::113:25c:47878] [client 2a02:1778::113:25c] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||letmespeakpodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "letmespeakpodcast.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZvL3-M1OIQ8W2Do6BLDhHwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-09-24 16:15:20
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 24 12:15:16.960868 2024] [security2:error] [pid 7844:tid 7844] [client 2a02:1778::113:25c:54606] [client 2a02:1778::113:25c] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sonarweapons.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sonarweapons.info"] [uri "/wp-json/wp/v2/users"] [unique_id "ZvLllFyl4U3vwB1hJEi2lwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-09-24 15:55:46
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:25c (ipv6.s151.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 24 11:55:39.987332 2024] [security2:error] [pid 12812:tid 12812] [client 2a02:1778::113:25c:42710] [client 2a02:1778::113:25c] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||xoticxpressions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "xoticxpressions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZvLg-wDLjBKjSbE871fTwwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack