๐บ๐ธ
TPI-Abuse
2026-09-23 14:12:17
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:12:12.856367 2026] [security2:error] [pid 3829:tid 3835] [client 2a02:2479:3b:4f00::1:35770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativedemocrat.aafm.us"] [uri "/wp-config.php.bak"] [unique_id "arPePGkB6mSwpakAR18u_QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 11:31:05
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-18 09:08:17
(5 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-17 04:40:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:40:36.950375 2026] [security2:error] [pid 31234:tid 31234] [client 2a02:2479:3b:4f00::1:48488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cnphilos.com"] [uri "/wp-config.php.bak"] [unique_id "aqtvRFPgcD1oVPlreC-4xwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-17 04:32:48
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 03:08:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:08:18.366571 2026] [security2:error] [pid 21207:tid 21207] [client 2a02:2479:3b:4f00::1:44218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morninginc.com"] [uri "/wp-config.php.save"] [unique_id "aqtZokzCi_bDnwjuEmAvwwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:13:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:13:04.709000 2026] [security2:error] [pid 29773:tid 29773] [client 2a02:2479:3b:4f00::1:55070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tenmenband.com"] [uri "/wp-config.php~"] [unique_id "aqtMsHZrdeyWEYuw5ysKIgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
strefapi_com
2026-09-17 01:45:08
(1 week ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 01:42:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:42:48.466992 2026] [security2:error] [pid 14188:tid 14272] [client 2a02:2479:3b:4f00::1:56290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rawhabitat.com"] [uri "/wp-config.php.bak"] [unique_id "aqtFmFzWrjP-0_ynNOHcMgAAAcE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
VanKoh
2026-09-17 01:22:26
(1 week ago)
2a02:2479:3b:4f00::1 - - [16/Sep/2026:19:22:23 -0600] "GET /wp-json/gravitysmtp/v1/tests/mock-data?p ...
show more
2a02:2479:3b:4f00::1 - - [16/Sep/2026:19:22:23 -0600] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:2479:3b:4f00::1 - - [16/Sep/2026:19:22:24 -0600] "GET /?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:2479:3b:4f00::1 - - [16/Sep/2026:19:22:25 -0600] "GET /index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Port Scan
Web App Attack
๐ฉ๐ช
4server
2026-09-17 01:02:06
(1 week ago)
[ThuSep1703:02:03.6554232026][security2:error][pid1454286:tid1454412][client2a02:2479:3b:4f00::1:0]M ...
show more
[ThuSep1703:02:03.6554232026][security2:error][pid1454286:tid1454412][client2a02:2479:3b:4f00::1:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"risparmiocasasuisse.ch\"][uri\"/wp-config.php.bak\"][unique_id\"aqs8C8s2J8OvsrAyDhkVgwAAAQo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 00:41:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 20:41:51.699879 2026] [security2:error] [pid 23537:tid 23537] [client 2a02:2479:3b:4f00::1:39236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kporterdesign.com"] [uri "/wp-config.php.bak"] [unique_id "aqs3T_MgQeRpsttQVyqR1wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
SOC [GOLINE SA]
2026-09-16 13:04:09
(1 week ago)
FortiGate IPS: React.Server.Components.react-flight.Remote.Code.Execution (severity high)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-08 03:03:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:2479:3b:4f00::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:03:28.647829 2026] [security2:error] [pid 3204:tid 3204] [client 2a02:2479:3b:4f00::1:56874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgtek.com"] [uri "/wp-config.php.bak"] [unique_id "ap97AGqa8QTkAVPF8VO_awAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-08 02:00:05
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack