|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 31.134.5.123 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.5.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:06:38.752707 2026] [security2:error] [pid 11931:tid 11931] [client 31.134.5.123:64183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abcollie.com"] [uri "/.wp-config.php.swp"] [unique_id "ahA4vq0anqIv0UGXsUOHtQAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 31.134.5.123 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.5.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 14:30:37.592978 2026] [security2:error] [pid 26939:tid 26939] [client 31.134.5.123:11357] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kawkacevents.com"] [uri "/wp-config.txt"] [unique_id "ag39ze52aoPYA1Io5tIZCAAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 31.134.5.123 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.5.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:57:01.743007 2026] [security2:error] [pid 7378:tid 7378] [client 31.134.5.123:22845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonesband.com"] [uri "/wp-config.php.bak"] [unique_id "ag2vnXnndVho6jykhjQxDgAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
31.134.5.123 - - [16/May/2026:20:57:02 +0200] "GET /wp-config.php.save HTTP/1.0" 404 182351 "-" "Moz ...
show more
31.134.5.123 - - [16/May/2026:20:57:02 +0200] "GET /wp-config.php.save HTTP/1.0" 404 182351 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15"
31.134.5.123 - - [16/May/2026:20:57:02 +0200] "GET /wp-config.php.bak HTTP/1.0" 404 182350 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15"
31.134.5.123 - - [16/May/2026:20:57:04 +0200] "GET /wp-config.php~ HTTP/1.0" 404 182347 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15"
31.134.5.123 - - [16/May/2026:20:57:05 +0200] "GET /wp-config.php.txt HTTP/1.0" 404 182350 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15"
31.134.5.123 - - [16/May/2026:20:57:05 +0200] "GET /wp-config.php.old HTTP/1.0" 404 182350 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7
...
show less
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
floreriaexpress
|
|
FakeADS-Anti: country:RU | https://floreriaexpresschile.cl/wp-signup.php
|
Bad Web Bot
|
|
|
๐ฉ๐ช
LRob.fr
|
|
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
|
Bad Web Bot
|
|
|
๐ฉ๐ช
paissangroup
|
|
Multiple WAF Violations
|
Web App Attack
|
|
|
๐ฉ๐ช
Packets-Decreaser.NET
|
|
Incoming Layer 7 Flood Detected
|
DDoS Attack
Web Spam
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 31.134.5.123 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.5.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 20:04:57.328193 2025] [security2:error] [pid 31587:tid 31611] [client 31.134.5.123:37419] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cmykdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cmykdesign.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQagKWH7mu2s8m4SlLssqgAAABY"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
fbarela
|
|
FortiGate SSL VPN login failures.
|
Hacking
Brute-Force
|
|