๐ซ๐ฎ
as211431.net
2026-09-16 08:11:58
(1 hour ago)
Triggered Cloudflare WAF (linkMaze) from FR.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from FR.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 07:20:38
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:20:31.913317 2026] [security2:error] [pid 14738:tid 14738] [client 2a02:4780:7:d72c::1:57400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.env.old"] [unique_id "aqpDPxwsuWNrIrZhT9b6_gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:43:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:43:27.897565 2026] [security2:error] [pid 11916:tid 11916] [client 2a02:4780:7:d72c::1:38146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgtek.com.smogsandiego.com"] [uri "/wp-config.php.old"] [unique_id "aqo6j9BVZ08fqXQkCvOjcgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:39:21
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:39:15.250894 2026] [security2:error] [pid 3351:tid 3351] [client 2a02:4780:7:d72c::1:60266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahamradio.com"] [uri "/wp-config.php~"] [unique_id "aqm7A7HzPrTS713bF3qsHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jasperedv.de
2026-09-14 16:42:56
(1 day ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-14 15:33:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 11:32:57.362460 2026] [security2:error] [pid 3917:tid 3917] [client 2a02:4780:7:d72c::1:50882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "415test.com"] [uri "/wp-config.php.old"] [unique_id "aqgTqc5N0HFqU6GqVZDJ9AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 15:14:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 11:14:37.086449 2026] [security2:error] [pid 11187:tid 11232] [client 2a02:4780:7:d72c::1:38544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tkfay.com"] [uri "/wp-config.php.orig"] [unique_id "aqgPXXypyl0Er_Bjk1IKjwAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 13:50:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 09:50:04.389918 2026] [security2:error] [pid 31880:tid 31880] [client 2a02:4780:7:d72c::1:42076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modalguitarist.com"] [uri "/wp-config.php.bak"] [unique_id "aqf7jKpwtsp3rtGlPRt_OAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 13:45:18
(1 day ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /index.php
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 09:50:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:50:48.369786 2026] [security2:error] [pid 15222:tid 15227] [client 2a02:4780:7:d72c::1:39116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.georgementz.org"] [uri "/wp-config.php.txt"] [unique_id "aqfDeNj3hkaDaptH-xffrgAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-14 09:46:30
(1 day ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:4780:7:d72c::1 - - [14/Sep/2026:11:46:29 +0200] "GET /wp-config.php.save HTTP/1.1" 404 23798 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 22:06:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:05:58.718758 2026] [security2:error] [pid 2275:tid 2275] [client 2a02:4780:7:d72c::1:53882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drwolberg.com"] [uri "/wp-config.php.swp"] [unique_id "aqceRhdZyMWyoHtPRAvmRgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 16:19:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:18:56.862143 2026] [security2:error] [pid 11445:tid 11445] [client 2a02:4780:7:d72c::1:58674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jonleefamily.brushmileage.org"] [uri "/wp-config.php.bak"] [unique_id "aqbM8BzAPWMkeTzP9oJi6AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 13:14:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:13:55.556014 2026] [security2:error] [pid 32205:tid 32205] [client 2a02:4780:7:d72c::1:33986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oliverhardy.com"] [uri "/wp-config.php.orig"] [unique_id "aqahk4gxX_QmuagRakNQxAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-13 03:30:05
(3 days ago)
Probing websites for vulnerabilities
Web App Attack