🇫🇷
COMAITE
2026-09-04 06:43:02
(4 hours ago)
SQL injection attempt from 31.134.1.13.
Web App Attack
🇺🇸
mnsf
2026-05-21 07:06:59
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 21:20:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 17:20:28.783064 2026] [security2:error] [pid 27532:tid 27532] [client 31.134.1.13:11317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.garanta.co.bamedica.com"] [uri "/wp-config.php.bak"] [unique_id "ag4lnMni4OAqHaOkjDl-SQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 17:59:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 13:59:45.062551 2026] [security2:error] [pid 16834:tid 16834] [client 31.134.1.13:13647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "partners.imagineyourphotos.com"] [uri "/wp-config.txt"] [unique_id "ag32kdTHidIfGWl13PBKaQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 16:49:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:49:18.277035 2026] [security2:error] [pid 15536:tid 15550] [client 31.134.1.13:44665] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomithai.com"] [uri "/wp-config.php.dist"] [unique_id "ag3mDjEqR1DVDZmczhCCewAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 16:21:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:21:30.089330 2026] [security2:error] [pid 17051:tid 17051] [client 31.134.1.13:49623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomslawmd.com"] [uri "/wp-config.php.save"] [unique_id "ag3fis1yY8Sg60sbpyKz2gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 14:50:50
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 10:50:43.001289 2026] [security2:error] [pid 16631:tid 16631] [client 31.134.1.13:44757] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.coolcustomweddingproducts.benshermanguitar.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.coolcustomweddingproducts.benshermanguitar.com"] [uri "/wp-config.inc"] [unique_id "ag3KQigxccg0tMttbexmtgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 12:04:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:04:35.128021 2026] [security2:error] [pid 32044:tid 32044] [client 31.134.1.13:27391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturalhomebuilders.com"] [uri "/wp-config.php.dist"] [unique_id "ag2jUy8_8unaNyQQg4xW1wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇼
taiwanfrp.me
2026-02-23 11:06:31
(6 months ago)
taiwanfrp NewUserConn auto-ban: reason=ip_over_target_scan_limit_60s1, conn10s=1, targets10m=1, targ ...
show more
taiwanfrp NewUserConn auto-ban: reason=ip_over_target_scan_limit_60s1, conn10s=1, targets10m=1, target=proxy:kiwicanary.MinecraftJava62owefeewfewfew|port:-
show less
Port Scan
Hacking
🇺🇸
TPI-Abuse
2025-12-16 16:49:14
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 31.134.1.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 16 11:49:09.131780 2025] [security2:error] [pid 28105:tid 28105] [client 31.134.1.13:65377] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.powerastronomy.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.powerastronomy.com"] [uri "/Runequest/doku.php"] [unique_id "aUGNhS7_KYp9dgwT75P30QAAAAI"], referer: http://www.powerastronomy.com/Runequest/doku.php?id=cat888_bet&do=register
show less
Brute-Force
Bad Web Bot
Web App Attack