π§πͺ
cmbplf
2026-08-23 07:40:33
(6 hours ago)
107 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
π©πͺ
Petros Stefanakis
2026-08-23 01:51:50
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 38.88.124.101 (CA/Canada/-)
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-23 01:08:07
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 21:08:01.255058 2026] [security2:error] [pid 17365:tid 17365] [client 38.88.124.101:35274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ruthbalser.org"] [uri "/wp-config.php_orig"] [unique_id "aopH8Xr9UJq3X92h6PPcVgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-08-22 22:23:06
(16 hours ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 38.88.124.101 (CA/Canada/-): 3 in the last 360 ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 38.88.124.101 (CA/Canada/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/23 00:23:02 [error] 3995471#3995471: *2676683 access forbidden by rule, client: 38.88.124.101, server: pescarafestival.it, request: "GET /wp-config.php.old HTTP/1.1", host: "www.pescarafestival.it"
2026/08/23 00:23:02 [error] 3995461#3995461: *2676685 access forbidden by rule, client: 38.88.124.101, server: pescarafestival.it, request: "GET /wp-config.php.swp HTTP/1.1", host: "www.pescarafestival.it"
2026/08/23 00:23:02 [error] 3995469#3995469: *2676686 access forbidden by rule, client: 38.88.124.101, server: pescarafestival.it, request: "GET /.wp-config.php.swp HTTP/1.1", host: "www.pescarafestival.it"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-08-22 16:23:43
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 12:23:36.033590 2026] [security2:error] [pid 14335:tid 14335] [client 38.88.124.101:50326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.laura-stone.com"] [uri "/wp-config.php.html"] [unique_id "aonNCJzDmbfOffFChc5A3AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 14:24:34
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:24:28.382503 2026] [security2:error] [pid 5258:tid 5258] [client 38.88.124.101:46462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jerryfeil.com"] [uri "/wp-config.php.dist"] [unique_id "aomxHJObn7L1cQgOWheiTQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-08-22 14:17:07
(1 day ago)
Aggressive web search of vulnerable pages: /wp-config.php.orig /wp-config.php.inc /wp-config.php.BAK ...
show more
Aggressive web search of vulnerable pages: /wp-config.php.orig /wp-config.php.inc /wp-config.php.BAK /wp-config.php.SAVE /wp-config.php.old /wp ...
show less
Web App Attack
π©πͺ
itsolon
2026-08-22 12:55:11
(1 day ago)
[22/Aug/2026:14:54:56 +0200] 178740329635.655651 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:14:5 ...
show more
[22/Aug/2026:14:54:56 +0200] 178740329635.655651 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:14:55:08 +0200] 178740330854.576047 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:14:55:08 +0200] 178740330857.960003 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:14:55:08 +0200] 178740330892.182140 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:14:55:09 +0200] 178740330935.250901 38.88.124.101 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 12:31:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:30:58.149652 2026] [security2:error] [pid 31756:tid 31756] [client 38.88.124.101:45726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.holgerfeld.com"] [uri "/wp-config.php.dist"] [unique_id "aomWgubVMfefsAI-fWE_4gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
XICTRON
2026-08-22 12:20:05
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
πΏπ¦
conure.sh
2026-08-22 10:32:13
(1 day ago)
csagent: score 20.5: wp-config backup grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 10:17:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 38.88.124.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:17:21.085373 2026] [security2:error] [pid 9079:tid 9079] [client 38.88.124.101:57634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fusteriafontane.com"] [uri "/wp-config.php.dist"] [unique_id "aol3MV9z7BKQ4HLSEgRZuAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
itsolon
2026-08-22 08:25:55
(1 day ago)
[22/Aug/2026:10:25:43 +0200] 178738714383.246977 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:10:2 ...
show more
[22/Aug/2026:10:25:43 +0200] 178738714383.246977 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:10:25:52 +0200] 178738715214.452832 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:10:25:52 +0200] 178738715229.012897 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:10:25:52 +0200] 17873871523.827159 38.88.124.101 0 217.154.7.177 443
[22/Aug/2026:10:25:52 +0200] 178738715229.549316 38.88.124.101 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π·π΄
iulianh
2026-08-22 05:11:53
(1 day ago)
80,443
Brute-Force
SSH
πΊπΈ
mnsf
2026-08-22 05:05:12
(1 day ago)
Abuse Detected (11)
Brute-Force
Web App Attack