|
๐ซ๐ท
tecnicorioja
|
|
(Mod_security)
|
Web App Attack
Brute-Force
Bad Web Bot
|
|
|
๐ฌ๐ง
thetomtaylor.co.uk
|
|
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,wa01,wa02]
|
Hacking
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 13:33:24.597837 2026] [security2:error] [pid 25861:tid 25861] [client 45.61.130.123:60644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gracebaptisthartsville.com"] [uri "/wp-config.php2"] [unique_id "aiRZ5HgUaQ3SoNn0C0cROAAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ฟ
ddw
|
|
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
|
Web App Attack
|
|
|
๐ฉ๐ช
ut-addicted.com
|
|
\[Sat Jun 06 18:59:53.210140 2026\] \[:error\] \[pid 15324:tid 139785758783232\] \[client 45.61.130. ...
show more
\[Sat Jun 06 18:59:53.210140 2026\] \[:error\] \[pid 15324:tid 139785758783232\] \[client 45.61.130.123:50625\] \[client 45.61.130.123\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "ut-addicted.com"\] \[uri "/wp-config.php2"\] \[unique_id "aiRSCYLwCt6uFbEx8z6u3gAAAQ4"\]
show less
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 12:59:30.015231 2026] [security2:error] [pid 20428:tid 20428] [client 45.61.130.123:61141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "math1on1.net"] [uri "/wp-config.php2"] [unique_id "aiRR8mbMxsJD3tVXXfl0EQAAABI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 12:44:27.931534 2026] [security2:error] [pid 23423:tid 23423] [client 45.61.130.123:61631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ibermar.info"] [uri "/wp-config.php2"] [unique_id "aiROa8xsjQpkiFXYUzwhFQAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
Lino Project
|
|
45.61.130.123 - - [06/Jun/2026:18:32:31 +0200] "GET /wp-config.php2 HTTP/1.1" 403 359 "-" "Python-ur ...
show more
45.61.130.123 - - [06/Jun/2026:18:32:31 +0200] "GET /wp-config.php2 HTTP/1.1" 403 359 "-" "Python-urllib/2.7"
...
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 12:26:31.048136 2026] [security2:error] [pid 987:tid 987] [client 45.61.130.123:50014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeremyscraig.com"] [uri "/wp-config.php2"] [unique_id "aiRKN7IqS84CKAGmaC07lgAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
LRob.fr
|
|
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
|
Bad Web Bot
|
|
|
๐ซ๐ท
masterguru
|
|
Restricted File Access Attempt. Matched phrase "wp-config." at REQUEST_FILENAME. (930130-197)
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 12:10:36.534071 2026] [security2:error] [pid 17342:tid 17342] [client 45.61.130.123:51954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructiondomex.com"] [uri "/wp-config.php2"] [unique_id "aiRGfOtpSXZ06HwXbzbb3QAAAAQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
mnsf
|
|
Abuse Detected (3)
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ฎ
YF
|
|
WordPress config file probe
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.130.123 (123.130.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 11:47:51.494050 2026] [security2:error] [pid 3838:tid 3838] [client 45.61.130.123:64732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manosentuayuda.org"] [uri "/wp-config.php2"] [unique_id "aiRBJ1_sEWHzP4wYwxmNDwAAABE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|