๐บ๐ธ
TPI-Abuse
2026-09-23 11:27:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 07:26:48.622256 2026] [security2:error] [pid 28798:tid 28820] [client 2a02:4780:7:d72c::1:42306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vinylnotespodcast.com"] [uri "/wp-config.php.save"] [unique_id "arO3eIKmrIgk9Q5zeXsfWQAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 03:25:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 23:25:30.781721 2026] [security2:error] [pid 29078:tid 29078] [client 2a02:4780:7:d72c::1:54210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tttns.com"] [uri "/about-jason//wp-config.php.bak"] [unique_id "arNGqnT-i-e0Q9y0BamRXgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 01:21:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:20:55.660636 2026] [security2:error] [pid 1264:tid 1264] [client 2a02:4780:7:d72c::1:37326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spacebooger.com.mms-boss.net"] [uri "/wp-config.php.save"] [unique_id "arMpd01onpJrHX9ys-1_9gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:54:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:54:45.821942 2026] [security2:error] [pid 27629:tid 27629] [client 2a02:4780:7:d72c::1:37450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desdier.com"] [uri "/wp-config.php.orig"] [unique_id "arMjVVnsd4AGWOY3EgJsKwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:36:23
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:36:19.976231 2026] [security2:error] [pid 15929:tid 15929] [client 2a02:4780:7:d72c::1:42322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianwhitty.com"] [uri "/wp-config.php.bak"] [unique_id "arMfA1kCf_nB7UNFAQ9xaAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 23:20:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:20:45.567897 2026] [security2:error] [pid 15809:tid 15857] [client 2a02:4780:7:d72c::1:49736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reghay.com"] [uri "/wp-config.php.bak"] [unique_id "arMNTf7DGBg3Q0wF2JapJwAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-18 22:01:16
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
filstal.org
2026-09-17 14:45:15
(3 weeks ago)
Web exploit or injection attempt blocked by ModSecurity WAF.
SQL Injection
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 12:38:07
(3 weeks ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:4780:7:d72c::1 - - [17/Sep/2026:14:37:52 +0200] "GET /.env.txt HTTP/1.1" 200 3509 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 11:53:06
(3 weeks ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:4780:7:d72c::1 - - [16/Sep/2026:13:52:51 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 6375 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-16 08:11:58
(3 weeks ago)
Triggered Cloudflare WAF (linkMaze) from FR.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from FR.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 07:20:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:20:31.913317 2026] [security2:error] [pid 14738:tid 14738] [client 2a02:4780:7:d72c::1:57400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.env.old"] [unique_id "aqpDPxwsuWNrIrZhT9b6_gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:43:33
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:43:27.897565 2026] [security2:error] [pid 11916:tid 11916] [client 2a02:4780:7:d72c::1:38146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgtek.com.smogsandiego.com"] [uri "/wp-config.php.old"] [unique_id "aqo6j9BVZ08fqXQkCvOjcgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:39:21
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:7:d72c::1 (srv1569167.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:39:15.250894 2026] [security2:error] [pid 3351:tid 3351] [client 2a02:4780:7:d72c::1:60266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahamradio.com"] [uri "/wp-config.php~"] [unique_id "aqm7A7HzPrTS713bF3qsHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jasperedv.de
2026-09-14 16:42:56
(3 weeks ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force