๐บ๐ธ
TPI-Abuse
2026-09-16 15:21:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.7.203.246 (ec2-3-7-203-246.ap-south-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.7.203.246 (ec2-3-7-203-246.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:21:47.794746 2026] [security2:error] [pid 4454:tid 4454] [client 3.7.203.246:54320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saynotoofland.org"] [uri "/wp-config.php.bak"] [unique_id "aqq0C7xNgKacrgtmVC4wEQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:55:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.7.203.246 (ec2-3-7-203-246.ap-south-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.7.203.246 (ec2-3-7-203-246.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:55:11.991535 2026] [security2:error] [pid 15414:tid 15422] [client 3.7.203.246:47978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.georgementz.org"] [uri "/wp-config.php.bak"] [unique_id "aqqfv0hCLAMrXHKLH_bjQgAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Pingger Shikkoken
2026-09-16 12:30:16
(3 days ago)
2026-09-16T12:30:16+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC ...
show more
2026-09-16T12:30:16+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=3.7.203.246 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=58750 DF PROTO=TCP SPT=37850 DPT=443 WINDOW=62727 RES=0x00 SYN URGP=0 2026-09-16T12:30:17+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=3.7.203.246 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=58751 DF PROTO=TCP SPT=37850 DPT=443 WINDOW=62727 RES=0x00 SYN URGP=0 2026-09-16T12:30:18+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=3.7.203.246 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=58752 DF PROTO=TCP SPT=37850 DPT=443 WINDOW=62727 RES=0x00 SYN URGP=0 ...
show less
Hacking
Bad Web Bot
๐ณ๐ฑ
BlueWire Hosting
2026-09-16 12:28:43
(3 days ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-09-16 09:53:45
(4 days ago)
Probing websites for vulnerabilities
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-16 09:21:29
(4 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-json (Match: /wp-json)
show less
Hacking
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 09:03:38
(4 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
๐ฉ๐ช
jbcrn
2026-09-16 08:42:49
(4 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 05:04:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 3.7.203.246 (ec2-3-7-203-246.ap-south-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.7.203.246 (ec2-3-7-203-246.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:03:58.562302 2026] [security2:error] [pid 31865:tid 31865] [client 3.7.203.246:47892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharawi-gum.com"] [uri "/wp-config.php.bak"] [unique_id "aqojPtk42nrV1yEr8_KDkQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-16 04:34:29
(4 days ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:18:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 3.7.203.246 (ec2-3-7-203-246.ap-south-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.7.203.246 (ec2-3-7-203-246.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:18:23.674083 2026] [security2:error] [pid 23481:tid 23481] [client 3.7.203.246:36366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "femalegamblers.org"] [uri "/wp-config.php.bak"] [unique_id "aqoYj7t8tgdG59GI8v9r1wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 03:30:03
(4 days ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-16 02:42:16
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-09-16 00:22:06
(4 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 3.7.203.246 (IN/India/ec2-3-7-203-246 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 3.7.203.246 (IN/India/ec2-3-7-203-246.ap-south-1.compute.amazonaws.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฆ๐บ
2000cn.com.au
2026-09-15 22:05:21
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking