Anonymous
2026-09-18 02:00:31
(1 day ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 05:28:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:28:49.395572 2026] [security2:error] [pid 9087:tid 9087] [client 3.13.253.203:56542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spacebooger.com.mms-boss.net"] [uri "/wp-config.php.bak"] [unique_id "aqt6kQIYuzwyNtZmxNLQPQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 04:25:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:25:54.392684 2026] [security2:error] [pid 9170:tid 9170] [client 3.13.253.203:57816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.kbalan.com"] [uri "/wp-config.php.bak"] [unique_id "aqtr0mB3h7GUmkCuKcoE_QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 06:37:10
(3 days ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐ญ๐ท
bubausluge
2026-09-16 06:32:12
(3 days ago)
Blocked by https://aegis.hr โ WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-09-16 ...
show more
Blocked by https://aegis.hr โ WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-09-16 06:13:34 to 2026-09-16 06:13:34
show less
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-09-16 06:27:04
(3 days ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 3.13.253.203 - - [16/Sep/2026:08:26:52 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 5730 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:17:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:17:27.371233 2026] [security2:error] [pid 27995:tid 28038] [client 3.13.253.203:51956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "plumeraproductions.com"] [uri "/wp-config.php.bak"] [unique_id "aqo0d-mK0zr7P8_NYph2jQAAAco"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-16 05:56:47
(3 days ago)
csagent: score 19.0: wp-config backup grab x2, 404 noise floor x1; 1 domain(s) in 24s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 05:06:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:06:12.390284 2026] [security2:error] [pid 19194:tid 19194] [client 3.13.253.203:59042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southsideaccountingservices.com"] [uri "/wp-config.php~"] [unique_id "aqojxMT4TPj2RFITDqjOxAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-09-16 04:46:29
(3 days ago)
3.13.253.203 - - [16/Sep/2026:12:45:03 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 56009 "-" "Mozil ...
show more
3.13.253.203 - - [16/Sep/2026:12:45:03 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 56009 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
3.13.253.203 - - [16/Sep/2026:12:45:09 +0800] "GET /wp-config.php~ HTTP/1.1" 404 56031 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
3.13.253.203 - - [16/Sep/2026:12:45:30 +0800] "GET /wp-config.php.save HTTP/1.1" 404 56009 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
3.13.253.203 - - [16/Sep/2026:12:45:52 +0800] "GET /wp-config.php.old HTTP/1.1" 404 56031 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
3.13.253.203 - - [16/Sep/2026:12:45:55 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 56009 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 04:33:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:33:19.190360 2026] [security2:error] [pid 12651:tid 12651] [client 3.13.253.203:58442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fractalsky.com"] [uri "/wp-config.php.bak"] [unique_id "aqocD1kRDChq3SzdfsDIdwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:17:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:17:29.395863 2026] [security2:error] [pid 6175:tid 6175] [client 3.13.253.203:49320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eta-mct.com"] [uri "/wp-config.php.bak"] [unique_id "aqoYWeyqX9bhlbxgzvfs_wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 03:35:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-16 03:33:27
(3 days ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.teory.gr; logs=/var/log/httpd/domains/teory.gr.log; samp ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.teory.gr; logs=/var/log/httpd/domains/teory.gr.log; samples=/wp-config.php.bak | /wp-config.php~ | /wp-config.php.save
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:21:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.13.253.203 (ec2-3-13-253-203.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:21:32.436862 2026] [security2:error] [pid 15981:tid 15981] [client 3.13.253.203:37496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "losbarbarosdelnorte.com"] [uri "/wp-config.php.bak"] [unique_id "aqoLPOGjicP5vq4DMsqC5AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack