๐ณ๐ฑ
Site.eu
2026-07-23 23:18:52
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
consul.to
2026-07-23 21:23:47
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-07-23 21:05:49
(1 day ago)
Multiple, malicious web requests detected
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-23 20:56:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 16:56:41.627918 2026] [security2:error] [pid 5613:tid 5613] [client 5.253.247.40:55417] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garanzuayrec.com"] [uri "/wp-includes/wp-config.php"] [unique_id "amKACc1tA3Uzg3zGfVuICgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 16:14:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 12:14:03.442250 2026] [security2:error] [pid 9223:tid 9236] [client 5.253.247.40:53428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robertbellamy.com"] [uri "/wp-includes/wp-config.php"] [unique_id "amI9y0HQ-zGoVpA8uTmXEQAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 14:38:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 10:38:27.830333 2026] [security2:error] [pid 2469429:tid 2469429] [client 5.253.247.40:54732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gcmmortgage.com"] [uri "/wp-includes/wp-config.php"] [unique_id "amInY5cZXBtHPuvleY687wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 11:17:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 07:17:43.438188 2026] [security2:error] [pid 2168933:tid 2168933] [client 5.253.247.40:63588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baysidechiropractic.net"] [uri "/wp-includes/wp-config.php"] [unique_id "amH4V48eRrgoyB9n1TgzvQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 06:27:53
(2 days ago)
[da.kdns.gr] httpd-suspicious-path: sites=www.geolystics.gr; logs=/var/log/httpd/domains/geolystics. ...
show more
[da.kdns.gr] httpd-suspicious-path: sites=www.geolystics.gr; logs=/var/log/httpd/domains/geolystics.gr.log; samples=/wp-content/plugins/enhanced-text-widget/analyst/src/403.php | /wp-content/plugins/pwnd/pwnd.php | /wp-content/users.php
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 06:24:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 02:24:13.132373 2026] [security2:error] [pid 1983715:tid 1983715] [client 5.253.247.40:51764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kawkacevents.com"] [uri "/wp-includes/wp-config.php"] [unique_id "amGzjUHLEaJdY5DXr8DMdQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:51:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:51:27.024195 2026] [security2:error] [pid 1979498:tid 1979498] [client 5.253.247.40:50675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffj.net"] [uri "/wp-includes/wp-config.php"] [unique_id "amGr34VwKXM_rDSbQMhZ7QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:23:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:23:30.050444 2026] [security2:error] [pid 3644562:tid 3644562] [client 5.253.247.40:50953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fibw.com"] [uri "/wp-includes/wp-config.php"] [unique_id "amGlUqx84DVcYW1-sKIiaQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-23 05:16:12
(2 days ago)
(upload_shell) srv102 PHP Shell Upload 5.253.247.40 (DE/Germany/40.247.253.5.in-addr.arpa): 1 in the ...
show more
(upload_shell) srv102 PHP Shell Upload 5.253.247.40 (DE/Germany/40.247.253.5.in-addr.arpa): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 04:22:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.247.40 (40.247.253.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:21:59.640142 2026] [security2:error] [pid 2147955:tid 2147955] [client 5.253.247.40:60383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "engravedweddingflutes.com"] [uri "/wp-includes/wp-config.php"] [unique_id "amGW55Tb0f7Kl1NRKqLrLgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 03:40:53
(2 days ago)
[redacted] 5.253.247.40 - - [23/Jul/2026:05:40:50 +0200] "GET /admin.php HTTP/1.1" 404 196 "-" "Mozi ...
show more
[redacted] 5.253.247.40 - - [23/Jul/2026:05:40:50 +0200] "GET /admin.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
[redacted] 5.253.247.40 - - [23/Jul/2026:05:40:50 +0200] "GET /adminfuns.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
[redacted] 5.253.247.40 - - [23/Jul/2026:05:40:51 +0200] "GET /admin/ HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 5.253.247.40 - - [23/Jul/2026:05:40:51 +0200] "GET /wp-admin/css/ HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
[redacted] 5.253.247.40 - - [23/Jul/2026:05:40:51 +0200] "GET /wp-admin/shell.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Geck
...
show less
Hacking
Web App Attack
๐จ๐ญ
zynex
2026-07-23 03:16:07
(2 days ago)
URL Probing: /adminfuns.php
Web App Attack