๐ฉ๐ช
Gwyneth Llewelyn
2026-09-16 17:43:02
(2 weeks ago)
2a06:6440:0:2cb6::1 - - [16/Sep/2026:18:43:00 +0100] "GET /roundcube/wp-json/gravitysmtp/v1/tests/mo ...
show more
2a06:6440:0:2cb6::1 - - [16/Sep/2026:18:43:00 +0100] "GET /roundcube/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/2.0" 404 994 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐ฉ๐ช
yitzhaq
2026-09-16 15:02:17
(2 weeks ago)
2a06:6440:0:2cb6::1 - - [16/Sep/2026:17:02:09 +0200] "GET / HTTP/1.1" 503 8351 "-" "Mozilla/5.0 (Win ...
show more
2a06:6440:0:2cb6::1 - - [16/Sep/2026:17:02:09 +0200] "GET / HTTP/1.1" 503 8351 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a06:6440:0:2cb6::1 - - [16/Sep/2026:17:02:10 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 4492 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a06:6440:0:2cb6::1 - - [16/Sep/2026:17:02:11 +0200] "POST /wp-json/batch/v1 HTTP/1.1" 403 4492 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a06:6440:0:2cb6::1 - - [16/Sep/2026:17:02:12 +0200] "POST /index.php?rest_route=/batch/v1 HTTP/1.1" 403 4493 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a06:6440:0:2cb6::1 - - [16/Sep/2026:17:02:13 +0200] "POST /index.php/wp-json/batch/v1 HTTP/1.1" 403 4492 "-" "Mozilla/5.0 (Windows NT 10.0; W
show less
Web App Attack
Hacking
Anonymous
2026-09-16 13:45:15
(2 weeks ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /index.php
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:30:00
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host. ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:29:52.454590 2026] [security2:error] [pid 17099:tid 17099] [client 2a06:6440:0:2cb6::1:19020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prayers4america.com"] [uri "/wp-config.php.bak"] [unique_id "aqqLwOeyBcvcnwrhb30tbwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 11:48:31
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host. ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:48:21.627311 2026] [security2:error] [pid 11991:tid 11991] [client 2a06:6440:0:2cb6::1:6144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grabagame.com"] [uri "/wp-config.php.bak"] [unique_id "aqqCBfYrc4r5cQUCL6-ZZgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-16 11:21:54
(2 weeks ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 7. First blocked: 2026-09-16.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 09:04:22
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host. ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:04:16.361519 2026] [security2:error] [pid 28885:tid 28885] [client 2a06:6440:0:2cb6::1:5346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.losbarbarosdelnorte.com"] [uri "/wp-config.php.bak"] [unique_id "aqpbkC-IlATZ-awYjlRULgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Omar Martรญnez
2026-09-16 07:27:23
(2 weeks ago)
2a06:6440:0:2cb6::1 - - [16/Sep/2026:01:27:22 -0600] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 7298 ...
show more
2a06:6440:0:2cb6::1 - - [16/Sep/2026:01:27:22 -0600] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 7298 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Phishing
Email Spam
Blog Spam
๐ฆ๐บ
2000cn.com.au
2026-09-16 05:04:37
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 04:05:36
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host. ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:05:29.140649 2026] [security2:error] [pid 2710:tid 2710] [client 2a06:6440:0:2cb6::1:52840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianwhitty.com"] [uri "/wp-config.php.bak"] [unique_id "aqoViV7R2dxcGJVaz1VNAQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SiyCah
2026-09-16 03:00:02
(2 weeks ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:57:11
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host. ...
show more
(mod_security) mod_security (id:949110) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:57:03.884790 2026] [security2:error] [pid 11747:tid 11747] [client 2a06:6440:0:2cb6::1:19948] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.delcano.org"] [uri "/wp-config.php.bak"] [unique_id "aqoFfxjWikB-WQ-CBiCcJQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:02:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host. ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:02:31.040897 2026] [security2:error] [pid 29079:tid 29079] [client 2a06:6440:0:2cb6::1:32228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hollywooddrummers.mikedeutsch.com"] [uri "/wp-config.php.bak"] [unique_id "aqnqp9W_Ouil5PQNb8-U5gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:17:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host. ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:6440:0:2cb6::1 (business-112.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:17:20.737872 2026] [security2:error] [pid 12451:tid 12454] [client 2a06:6440:0:2cb6::1:57370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gilesrentalcars.com"] [uri "/wp-config.php.bak"] [unique_id "aqngEEL9BGJr7jKAlgXLZgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-16 00:02:25
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: registry.budyn.xyz | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack