๐บ๐ธ
omc
2026-06-07 20:05:02
(3 days ago)
AH01797: Unauthorized file
Bad Web Bot
๐จ๐ญ
backslash
2026-05-24 15:42:00
(2 weeks ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-21 23:17:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 19:17:10.750133 2026] [security2:error] [pid 17057:tid 17057] [client 31.134.0.58:18043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.instagenii.ficklepassionproductions.com"] [uri "/wp-config.php.orig"] [unique_id "ag-SdvNBTgJy4Y-84CjvfQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-21 21:55:52
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 21:11:08
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 17:11:01.438901 2026] [security2:error] [pid 13088:tid 13088] [client 31.134.0.58:45479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ismaelcavazos.com"] [uri "/wp-config.php.orig"] [unique_id "ag4jZUJ9ScvCTCDVYnUW3gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 15:44:36
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 11:44:32.084044 2026] [security2:error] [pid 17435:tid 17435] [client 31.134.0.58:42571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.escapegeorgesrouquier.williamgilcher.com"] [uri "/wp-config.php.bak"] [unique_id "ag3W4HNcpnkO1PtOpl8PjwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 15:14:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 11:14:00.000115 2026] [security2:error] [pid 25682:tid 25706] [client 31.134.0.58:36831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.strengthsmatter.teritemme.com"] [uri "/wp-config.php~"] [unique_id "ag3Ptzief1UD2nw0WOORPQAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-06 09:09:32
(1 month ago)
Forum/form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-04-27 05:05:45
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 01:05:39.803056 2026] [security2:error] [pid 24607:tid 24607] [client 31.134.0.58:34113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||techlinks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "techlinks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae7uo3TCYejkYWpUkmeVqAAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-02 03:40:06
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.0.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 22:40:02.052128 2026] [security2:error] [pid 22155:tid 22155] [client 31.134.0.58:58925] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||admin.turedinmobiliaria.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "admin.turedinmobiliaria.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYAckpwC4wcuPYERbTbfCwAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-01-20 17:59:35
(4 months ago)
[redacted] 31.134.0.58 - - [20/Jan/2026:18:59:33 +0100] "GET /[redacted] HTTP/1.1" 302 1517 0/39796 ...
show more
[redacted] 31.134.0.58 - - [20/Jan/2026:18:59:33 +0100] "GET /[redacted] HTTP/1.1" 302 1517 0/39796 "https://[redacted]" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" [redacted] 31.134.0.58 - - [20/Jan/2026:18:59:34 +0100] "GET /[redacted] HTTP/1.1" 302 1517 0/24778 "https://[redacted]" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-01-13 00:02:05
(4 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 31.134.0.58 (SC/Seychelles/-): 2 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 31.134.0.58 (SC/Seychelles/-): 2 in the last 3600 secs
show less
Web App Attack
๐ธ๐ช
OnTheEdge
2025-11-30 02:14:17
(6 months ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐จ๐ฟ
lp
2025-11-29 16:23:10
(6 months ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 31.134.0.58
2025-11-29T12:25:39+01:00 ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 31.134.0.58
2025-11-29T12:25:39+01:00 vpn Access-Reject 'hesabres' station: 31.134.0.58 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-11-29T16:15:20+01:00 vpn Access-Reject 'i491971' station: 31.134.0.58 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-11-28 16:22:55
(6 months ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 31.134.0.58
2025-11-28T16:34:57+01:00 ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 31.134.0.58
2025-11-28T16:34:57+01:00 vpn Access-Reject 'demo' station: 31.134.0.58 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-11-28T16:42:45+01:00 vpn Access-Reject 'demoaccount' station: 31.134.0.58 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack