🇩🇪
BlueWire Hosting
2026-09-14 21:30:52
(5 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 19:43:48
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 15:43:44.406969 2026] [security2:error] [pid 8608:tid 8608] [client 2a02:4780:28:f7d4::1:52554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pcga.golf"] [uri "/wp-config.php.save"] [unique_id "aqhOcMiP1541FOROlptlbQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-14 19:37:01
(7 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-14 11:29:38
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 07:29:31.173515 2026] [security2:error] [pid 2626209:tid 2626209] [client 2a02:4780:28:f7d4::1:55726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troop9weymouth.com"] [uri "/wp-config.php~"] [unique_id "aqfamyLiOFIRWXYQ2VAp-AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 04:35:56
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 00:35:53.037797 2026] [security2:error] [pid 5542:tid 5542] [client 2a02:4780:28:f7d4::1:46630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salernospizza.com"] [uri "/wp-config.php.swp"] [unique_id "aqd5qQoi-9U2SavdYur6RwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 17:35:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 13:35:48.576280 2026] [security2:error] [pid 2783:tid 2783] [client 2a02:4780:28:f7d4::1:54872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ralphharris.org"] [uri "/wp-config.php.save"] [unique_id "aqbe9PJyKBP15TuJPJP4ywAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 13:45:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:45:22.566247 2026] [security2:error] [pid 976:tid 976] [client 2a02:4780:28:f7d4::1:49256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.indyham.com"] [uri "/wp-config.php.orig"] [unique_id "aqao8r5upfrykfMzqgs75QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 10:50:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 06:50:06.274656 2026] [security2:error] [pid 3246:tid 3246] [client 2a02:4780:28:f7d4::1:45734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.kbalan.com"] [uri "/wp-config.php.old"] [unique_id "aqZ_3jYmSLF3hckNvYFvuAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 05:00:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 01:00:08.587679 2026] [security2:error] [pid 31685:tid 31685] [client 2a02:4780:28:f7d4::1:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.top-brand.us"] [uri "/.env.old"] [unique_id "aqYt2KC7sYQwFpL0NIyeQgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-12 23:16:51
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.wtf | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 16:51:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 12:51:00.082705 2026] [security2:error] [pid 2730:tid 2730] [client 2a02:4780:28:f7d4::1:33940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wp.hotpay.co"] [uri "/wp-config.php.old"] [unique_id "aqWC9D0-3UGAZre0tj96sQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
jasperedv.de
2026-09-12 14:49:24
(2 days ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
🇮🇹
VHosting
2026-09-11 20:35:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 20:31:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:f7d4::1 (srv1751032.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 16:31:31.747570 2026] [security2:error] [pid 770:tid 770] [client 2a02:4780:28:f7d4::1:39810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brazilianbottom.com"] [uri "/wp-config.php.old"] [unique_id "aqRlI-f8iFwpfj8vpBIltwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack