🇺🇸
TPI-Abuse
2026-09-06 22:50:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:50:46.843449 2026] [security2:error] [pid 24035:tid 24035] [client 2a02:4780:4:a416::1:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ndanetworks.com"] [uri "/.env.swp"] [unique_id "ap3uRgxOv6O2N3C0H4XvuQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:56:54
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:56:47.453509 2026] [security2:error] [pid 24893:tid 24893] [client 2a02:4780:4:a416::1:36546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adlc18.mtalame.com"] [uri "/wp-config.php.bak"] [unique_id "ap2bT59yLoLNJUSl1Npi8AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-06 16:47:25
(11 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cluster.goblinpot.website | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:40:35
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:40:32.278075 2026] [security2:error] [pid 3414:tid 3414] [client 2a02:4780:4:a416::1:44492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puckerbackbikini.com"] [uri "/.hg/store/00manifest.i"] [unique_id "ap1tUPA4WJBouBKt1-iu6AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:57:27
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:57:23.027017 2026] [security2:error] [pid 4153406:tid 4153406] [client 2a02:4780:4:a416::1:35196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.automatebi.whitmarshinc.com"] [uri "/.git/HEAD"] [unique_id "ap05A5K3p6FCx12AH_kWbQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:02:30
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:02:25.980831 2026] [security2:error] [pid 12200:tid 12200] [client 2a02:4780:4:a416::1:51928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuentevictoria.com"] [uri "/wp-config.php.bak"] [unique_id "ap0sIdP2MHebY3id5lSqRwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:37:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:37:18.484224 2026] [security2:error] [pid 24381:tid 24381] [client 2a02:4780:4:a416::1:60154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "versallis.com"] [uri "/wp-config.php.bak"] [unique_id "apx9fpfQDICHl5CmtP7SyQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 14:31:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 10:31:51.110282 2026] [security2:error] [pid 3000:tid 3011] [client 2a02:4780:4:a416::1:33100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fastestcopyright.com"] [uri "/wp-config.php~"] [unique_id "apwn1wqt_MXQRF7vEyCbqAAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 12:29:10
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 10:15:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 06:15:49.313346 2026] [security2:error] [pid 22443:tid 22443] [client 2a02:4780:4:a416::1:35756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fredlandia.com"] [uri "/.env.save"] [unique_id "apvr1QCLe-mH5kpYpQieSAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 09:53:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 05:53:16.055641 2026] [security2:error] [pid 11286:tid 11286] [client 2a02:4780:4:a416::1:59880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.major33.com.cruanyes.com"] [uri "/.git/config"] [unique_id "apvmjP0DdTVDOZ_BORFBdAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 07:35:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 03:35:33.952148 2026] [security2:error] [pid 27724:tid 27724] [client 2a02:4780:4:a416::1:54642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehealthyplaceclayton.com"] [uri "/wp-config.php.old"] [unique_id "apvGRbfMrFYQnuwBMTZUjgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 03:15:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:4:a416::1 (srv1558415.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 23:15:21.817670 2026] [security2:error] [pid 10158:tid 10158] [client 2a02:4780:4:a416::1:50878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonesband.com"] [uri "/wp-config.php.save"] [unique_id "apuJSdEn_pXwI-LjS_LfgQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-04 21:53:19
(2 days ago)
Aggressive scanning resulting into 404
Bad Web Bot
🇨🇦
Anytech
2026-09-04 19:13:00
(2 days ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking