🇺🇸
TPI-Abuse
2026-09-15 09:59:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:59:35.308064 2026] [security2:error] [pid 4500:tid 4500] [client 2a02:4780:2d:ef7b::1:57540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "activethinkers.net"] [uri "/wp-config.php.save"] [unique_id "aqkXB1aRO3aXvmdJdNh6IwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 07:12:11
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:12:05.395731 2026] [security2:error] [pid 29294:tid 29294] [client 2a02:4780:2d:ef7b::1:58300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.heavenonearthonline.net"] [uri "/.env.txt"] [unique_id "aqjvxasTJ5b66BJRO5JKGgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 06:30:53
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:30:47.184374 2026] [security2:error] [pid 7141:tid 7141] [client 2a02:4780:2d:ef7b::1:41758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.deserttrails.net"] [uri "/.env.txt"] [unique_id "aqjmFzGRJHlytGMOCaScnQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 04:17:10
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:17:07.079779 2026] [security2:error] [pid 26363:tid 26363] [client 2a02:4780:2d:ef7b::1:43822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.asapstarsmogcheck.smogsandiego.com"] [uri "/wp-config.php~"] [unique_id "aqjGw8GLtZEycqTjcdb1FAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-15 03:50:06
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 01:46:41
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:46:35.533472 2026] [security2:error] [pid 25380:tid 25380] [client 2a02:4780:2d:ef7b::1:37968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ronjamestelevision.com"] [uri "/wp-config.php.orig"] [unique_id "aqije_3Ae8eB7X1Uh6qN4gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 22:52:59
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 18:52:55.165075 2026] [security2:error] [pid 24365:tid 24369] [client 2a02:4780:2d:ef7b::1:35436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.testproperty.pref-realestate.com"] [uri "/wp-config.php~"] [unique_id "aqh6x_AQabm85b9Pie-WfgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 17:31:44
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 13:31:35.584573 2026] [security2:error] [pid 20871:tid 20871] [client 2a02:4780:2d:ef7b::1:59314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aperturecontrols.com"] [uri "/.env.txt"] [unique_id "aqgvdxxytblZIiDjTyHKYgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-14 17:06:48
(21 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇮🇹
VHosting
2026-09-14 11:15:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇵🇱
strefapi_com
2026-09-14 10:24:47
(1 day ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 09:51:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:2d:ef7b::1 (srv805939.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:50:54.029595 2026] [security2:error] [pid 13020:tid 13033] [client 2a02:4780:2d:ef7b::1:53960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rawhabitat.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rawhabitat.com"] [uri "/db.sql"] [unique_id "aqfDfom8_75zQ5zm0XzxRwAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-14 02:01:54
(1 day ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:4780:2d:ef7b::1 - - [14/Sep/2026:04:01:53 +0200] "GET /wp-config.php.old HTTP/1.1" 404 29187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack