🇺🇸
TPI-Abuse
2026-09-13 04:07:52
(40 minutes ago)
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 00:07:45.563491 2026] [security2:error] [pid 28410:tid 28410] [client 4.201.220.58:28513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonegym.com"] [uri "/.env.old"] [unique_id "aqYhkRe1-OMxKiDKdBcjWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 03:37:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 23:37:33.959410 2026] [security2:error] [pid 17910:tid 17910] [client 4.201.220.58:4916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gerrytolentino.net"] [uri "/wp-config.php.bak"] [unique_id "aqYafV6iL7d0sm5a2iBQMQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-13 02:18:27
(2 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /api/session/properties | 2026-09-13 02:18 UTC
show less
Bad Web Bot
Anonymous
2026-09-12 20:26:20
(8 hours ago)
TACHIDE WEBEXPLOIT 4.201.220.58 (4.201.220.58)
Web App Attack
🇮🇹
www.tana.it
2026-09-12 18:28:30
(10 hours ago)
PHP scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 17:54:45
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 13:54:39.483971 2026] [security2:error] [pid 28320:tid 28320] [client 4.201.220.58:41385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crittergetterpestcontrol.com"] [uri "/wp-config.php.bak"] [unique_id "aqWR349JL_WkLAiDeCNixAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 16:30:59
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 12:30:54.877270 2026] [security2:error] [pid 12629:tid 12629] [client 4.201.220.58:32237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southsideaccountingservices.com"] [uri "/wp-config.php~"] [unique_id "aqV-Pn7hnb8-i1Su5Hse1wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 14:02:34
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 10:02:31.527272 2026] [security2:error] [pid 2624:tid 2624] [client 4.201.220.58:36681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gracebaptisthartsville.com"] [uri "/wp-config.php.save"] [unique_id "aqVbdxivTTdz00OBNXMg3wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 13:04:34
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:04:30.285930 2026] [security2:error] [pid 30588:tid 30644] [client 4.201.220.58:36092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mtiminis.com"] [uri "/.env.bak"] [unique_id "aqVN3utmFS6eNkBD98P59QAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-09-12 12:10:27
(16 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
ASN: 8075 (Microsoft Corporat ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
ASN: 8075 (Microsoft Corporation)
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-json/gravitysmtp/v1/tests/mock-data
Query: ?page=gravitysmtp-settings
Timestamp: 2026-09-12T10:57:27Z
Ray ID: a39e642ff8a9f1e7
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
🇿🇦
conure.sh
2026-09-12 10:48:51
(17 hours ago)
csagent: score 19.8: wp-config backup grab x2; 1 domain(s) in 4s
Web App Attack
🇸🇪
vaia.cloud
2026-09-12 09:00:03
(19 hours ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:56:36
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:56:30.687439 2026] [security2:error] [pid 14007:tid 14007] [client 4.201.220.58:40317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theamarals.com"] [uri "/wp-config.php.bak"] [unique_id "aqUTvq1No87CZx8so5vCtQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-12 05:07:27
(23 hours ago)
4.201.220.58 - - [12/Sep/2026:07:07:26 +0200] "GET /.svn/entries HTTP/1.1" 404 29187 "-" "Mozilla/5. ...
show more
4.201.220.58 - - [12/Sep/2026:07:07:26 +0200] "GET /.svn/entries HTTP/1.1" 404 29187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 05:06:45
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 4.201.220.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:06:37.841820 2026] [security2:error] [pid 5440:tid 5498] [client 4.201.220.58:36339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gipsongrocerystore.digital4z.com"] [uri "/wp-config.php.bak"] [unique_id "aqTd3UC-Fw2ZfhrYVtMRAQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack