πΊπΈ
TPI-Abuse
2026-07-29 15:04:49
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 51.120.69.65 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 51.120.69.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 11:04:40.623281 2026] [security2:error] [pid 3103454:tid 3103454] [client 51.120.69.65:45140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.deltasouls.com"] [uri "/wp-config.php"] [unique_id "amoWiLxaDlKJWBYIsusyXQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
rsa
2026-07-29 15:04:00
(2 minutes ago)
GET /rootx.php HTTP/1.1
DDoS Attack
Brute-Force
Exploited Host
Web App Attack
Hacking
Anonymous
2026-07-29 14:57:04
(9 minutes ago)
Bot / scanning and/or hacking attempts: GET /index.php HTTP/1.1, GET /wp-admin/css/mailer.php.php HT ...
show more
Bot / scanning and/or hacking attempts: GET /index.php HTTP/1.1, GET /wp-admin/css/mailer.php.php HTTP/1.1, GET /wp-admin/maint/mailer.php.php HTTP/1.1, GET /wp-includes/mailer.php HTTP/1.1, GET /wp-includes/css/mailer.php.php HTTP/1.1, GET /ym.php HTTP/1.1, GET /wp-admin/includes/mailer.php.php HTTP/1.1, GET /wp-content/mailer.php HTTP/1.1, GET /Alfa.php HTTP/1.1, GET /wp-admin/mailer.php HTTP/1.1, GET /pucci.php HTTP/1.1, GET /geforce.php HTTP/1.1, GET / HTTP/1.1, GET //f6.php HTTP/1.1, GET /?p= HTTP/1.1, GET /bthil.php HTTP/1.1, GET /11.php HTTP/1.1, GET //admin.php HTTP/1.1, GET /1.php HTTP/1.1, GET /inputs.php HTTP/1.1, GET /100.php HTTP/1.1, GET /about.php HTTP/1.1, GET //av.php HTTP/1.1, GET /8.php HTTP/1.1, GET /classwithtostring.php?p= HTTP/1.1, GET /7.php HTTP/1.1, GET /wp-content/admin.php HTTP/1.1, GET //edit.php HTTP/1.1
show less
Hacking
Web App Attack
π©πͺ
raph
2026-07-29 14:45:28
(20 minutes ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
πΊπΈ
jsjdmediallc
2026-07-29 14:40:05
(26 minutes ago)
Auto-blocked: score 1172 (threshold 10). Tier: CRITICAL. Hits: 558. Flags: empty-ua, error-scan, wp- ...
show more
Auto-blocked: score 1172 (threshold 10). Tier: CRITICAL. Hits: 558. Flags: empty-ua, error-scan, wp-login, config-file, wp-upgrade, webshell, wp-install, info-file, test-file, cgi-bin. Paths: /ucen.php, /anon.php, /bypas.php, /anonsec.php, /bypp.php
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 14:38:54
(27 minutes ago)
(mod_security) mod_security (id:210492) triggered by 51.120.69.65 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 51.120.69.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 10:38:51.023532 2026] [security2:error] [pid 532587:tid 532587] [client 51.120.69.65:62039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.calicoinc.com"] [uri "/wp-config.php"] [unique_id "amoQe3YzF4ETnQrp85I-3QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 14:32:58
(33 minutes ago)
XSS Attempt
Hacking
π³π±
ConsulHosting
2026-07-29 14:31:07
(35 minutes ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-07-29 14:28:39
(37 minutes ago)
Banned by Fail2Ban on server
Web App Attack
π©πͺ
Hazzard
2026-07-29 14:28:10
(37 minutes ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
π©πͺ
Ba-Yu
2026-07-29 14:28:03
(38 minutes ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
Lee Daniel
2026-07-29 14:18:43
(47 minutes ago)
51.120.69.65 - - [29/Jul/2026:10:18:37 -0400] "GET /by.php HTTP/1.1" 404 58085 "-" "-"
51.120.69.65 ...
show more
51.120.69.65 - - [29/Jul/2026:10:18:37 -0400] "GET /by.php HTTP/1.1" 404 58085 "-" "-"
51.120.69.65 - - [29/Jul/2026:10:18:38 -0400] "GET /cxs.php HTTP/1.1" 404 58086 "-" "-"
51.120.69.65 - - [29/Jul/2026:10:18:39 -0400] "GET /coffexium.php HTTP/1.1" 404 58092 "-" "-"
51.120.69.65 - - [29/Jul/2026:10:18:40 -0400] "GET /asdf.php HTTP/1.1" 404 58082 "-" "-"
51.120.69.65 - - [29/Jul/2026:10:18:42 -0400] "GET /red.php HTTP/1.1" 404 58086 "-" "-"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-07-29 14:16:43
(49 minutes ago)
20.590 requests in 1 hour (1mo4w3h)
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-29 14:11:49
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 51.120.69.65 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 51.120.69.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 10:11:41.386273 2026] [security2:error] [pid 664305:tid 664305] [client 51.120.69.65:7252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.agchurchkuwait.com"] [uri "/wp-config.php"] [unique_id "amoKHQhqw9xNUtdgRBglHwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 14:08:14
(57 minutes ago)
Multiple web server 400 error codes from same source ip
Web App Attack