๐บ๐ธ
TPI-Abuse
2026-09-16 09:46:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:46:34.066665 2026] [security2:error] [pid 26925:tid 26925] [client 2a02:4780:10:a645::1:46794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bamedica.com"] [uri "/wp-config.php.orig"] [unique_id "aqplerGC3hrI-cAyQ1P2NgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-16 07:20:58
(2 days ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:06:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:06:19.109067 2026] [security2:error] [pid 2512:tid 2512] [client 2a02:4780:10:a645::1:59048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guitarwisdom.com"] [uri "/wp-config.php.txt"] [unique_id "aqndez0cEzDF3eqy2DsyhgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:00:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:59:56.461232 2026] [security2:error] [pid 31347:tid 31347] [client 2a02:4780:10:a645::1:59596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.blackweddingnapkins.com"] [uri "/.env.bak"] [unique_id "aqmHnDLPuTp7VIJXliXMjQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:24:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:24:30.696932 2026] [security2:error] [pid 24424:tid 24424] [client 2a02:4780:10:a645::1:54480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.english.art.mavikalem.org"] [uri "/wp-config.php.swp"] [unique_id "aqkc3tmGLmjZEUk_GLOD3wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:38:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:37:55.871550 2026] [security2:error] [pid 32751:tid 336] [client 2a02:4780:10:a645::1:57832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gabegabel.prismatik.com"] [uri "/wp-config.php.txt"] [unique_id "aqkD44Qoy1qk-sKty23R0gAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 15:15:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:a645::1 (srv525210.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 11:15:02.811078 2026] [security2:error] [pid 22889:tid 22908] [client 2a02:4780:10:a645::1:59292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.worldecom.aafm.us"] [uri "/wp-config.php~"] [unique_id "aqgPdsYvfM4Hp7HPpjU_8wAAAhA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-14 08:24:39
(4 days ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐น
VHosting
2026-09-14 01:00:05
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack