🇧🇪
taivas.nl
2026-09-09 04:32:56
(1 day ago)
Many_bad_calls
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:02:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.com ...
show more
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:02:06.813587 2026] [security2:error] [pid 15232:tid 15232] [client 51.48.235.114:38944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nihlabs.org"] [uri "/wp-config.php~"] [unique_id "aqAHTmxCoGMZJ8Eb-8b3KQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-08 12:02:16
(2 days ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 11:38:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.com ...
show more
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:38:06.369951 2026] [security2:error] [pid 1996:tid 1996] [client 51.48.235.114:37456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.prostar.industries"] [uri "/wp-config.php.bak"] [unique_id "ap_znqrK4CaCWaZia_Nv7gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:35:02
(2 days ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:10:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.com ...
show more
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:10:32.063816 2026] [security2:error] [pid 1173:tid 1248] [client 51.48.235.114:60258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pilargarciamanzanares.com.clmtic.net"] [uri "/wp-config.php.bak"] [unique_id "ap_tKGDVg5evfFAZ-ynnAgAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
strefapi_com
2026-09-08 10:09:10
(2 days ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-08 09:06:56
(2 days ago)
PARMACOM WEBEXPLOIT 51.48.235.114 (ec2-51-48-235-114.eu-south-2.compute.amazonaws.com)
Web App Attack
Anonymous
2026-09-08 08:55:05
(2 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇫🇷
Octopuce
2026-09-08 08:22:43
(2 days ago)
Aggressive web search of vulnerable pages: /.env /phpinfo.php /info.php /test.php /backup.sql /backu ...
show more
Aggressive web search of vulnerable pages: /.env /phpinfo.php /info.php /test.php /backup.sql /backup.sql.gz /backup.zip ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:55:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.com ...
show more
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:55:23.305931 2026] [security2:error] [pid 16138:tid 16138] [client 51.48.235.114:45464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gracebaptisthartsville.com"] [uri "/wp-config.php.bak"] [unique_id "ap-_aykhBvsk6h_RsNc9GgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-08 06:56:11
(2 days ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TAY
2026-09-08 06:47:48
(2 days ago)
51.48.235.114 - - [08/Sep/2026:14:47:12 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 72066 "-" "Mozi ...
show more
51.48.235.114 - - [08/Sep/2026:14:47:12 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 72066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
51.48.235.114 - - [08/Sep/2026:14:47:34 +0800] "GET /wp-config.php.save HTTP/1.1" 404 72066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
51.48.235.114 - - [08/Sep/2026:14:47:36 +0800] "GET /wp-config.php.old HTTP/1.1" 404 72066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
51.48.235.114 - - [08/Sep/2026:14:47:39 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 72066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
51.48.235.114 - - [08/Sep/2026:14:47:41 +0800] "GET /wp-config.php.txt HTTP/1.1" 404 72066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTM
...
show less
Brute-Force
🇳🇱
maxxsense
2026-09-08 06:37:39
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 51.48.235.114 (ES/Spain/ec2-51-48-235-1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 51.48.235.114 (ES/Spain/ec2-51-48-235-114.eu-south-2.compute.amazonaws.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 06:28:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.com ...
show more
(mod_security) mod_security (id:210492) triggered by 51.48.235.114 (ec2-51-48-235-114.eu-south-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:28:22.075515 2026] [security2:error] [pid 25586:tid 25586] [client 51.48.235.114:38756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goodacoustic.com"] [uri "/wp-config.php.bak"] [unique_id "ap-rBma4pvCwxN5X1dEzUgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack