๐ฉ๐ช
raph
2026-09-16 02:18:47
(4 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 18:10:39
(13 hours ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.168.130.13 - - [15/Sep/2026:04:58:18 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 5927 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:49:14
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:49:11.105850 2026] [security2:error] [pid 13403:tid 13403] [client 35.168.130.13:51986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mardensmith.com"] [uri "/wp-config.php~"] [unique_id "aql3B0xKVEML1KTCtmwAhQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 14:19:47
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:19:39.836351 2026] [security2:error] [pid 20647:tid 20647] [client 35.168.130.13:36730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eta-mct.com"] [uri "/wp-config.php.orig"] [unique_id "aqlT-16NvFJ7XptakihOnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 18:28:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 14:27:57.766282 2026] [security2:error] [pid 22213:tid 22213] [client 35.168.130.13:51050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drgtek.com.smogsandiego.com"] [uri "/wp-config.php.bak"] [unique_id "aqg8rXxhgPr8EmbZiSDYrgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-14 17:43:52
(1 day ago)
[14/Sep/2026:20:43:52 +0300] -- 35.168.130.13 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-j ...
show more
[14/Sep/2026:20:43:52 +0300] -- 35.168.130.13 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 15:54:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 11:54:50.563986 2026] [security2:error] [pid 23196:tid 23196] [client 35.168.130.13:33328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fatcaverecords.fatcavemedia.com"] [uri "/wp-config.php.bak"] [unique_id "aqgYymjcIazJZa85HV-OsAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 10:37:01
(1 day ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.koukas-machines.com; logs=/var/log/httpd/domains/koukas- ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.koukas-machines.com; logs=/var/log/httpd/domains/koukas-machines.com.log; samples=/wp-config.php~
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 09:50:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:50:09.036615 2026] [security2:error] [pid 2759:tid 2759] [client 35.168.130.13:49204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fishleadership.org"] [uri "/wp-config.php.save"] [unique_id "aqfDUeSGyzLNKkOiWI2wkAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ช
Tsumugi Kotobuki
2026-09-14 06:07:30
(2 days ago)
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 57 | Len: 60B | Win: ...
show more
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 57 | Len: 60B | Win: 62727(1) | rDNS: ec2-35-168-130-13.compute-1.amazonaws.com | F2B/ufw-honeypot@2026-09-14T06:07:29Z
show less
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-14 06:01:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:01:06.082647 2026] [security2:error] [pid 13608:tid 13608] [client 35.168.130.13:53700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kbalan.com"] [uri "/wp-config.php.bak"] [unique_id "aqeNoswzrvRHKjwRMDUqtgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 02:03:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 22:03:25.756443 2026] [security2:error] [pid 17805:tid 17805] [client 35.168.130.13:41428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hydrometal-js.com"] [uri "/wp-config.php.txt"] [unique_id "aqdV7WcEdxMJzhHwe5MrCAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 01:19:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:19:40.559267 2026] [security2:error] [pid 6688:tid 6688] [client 35.168.130.13:43502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virantenn.com"] [uri "/wp-config.php~"] [unique_id "aqdLrBnGEE17oAb-oXoyzAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 23:35:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 19:35:05.513818 2026] [security2:error] [pid 30673:tid 30673] [client 35.168.130.13:45092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crittergetterpestcontrol.azcrittergetter.com"] [uri "/wp-config.php.bak"] [unique_id "aqczKYVdjjkWwZlAL9cvdQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 22:51:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 35.168.130.13 (ec2-35-168-130-13.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:51:33.762160 2026] [security2:error] [pid 27143:tid 27143] [client 35.168.130.13:39922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelmoorefield.com"] [uri "/wp-config.php.txt"] [unique_id "aqco9RW_w2Bu_QnqZp4ShwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack