🇺🇸
TPI-Abuse
2026-09-07 02:39:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:39:24.562303 2026] [security2:error] [pid 3195:tid 3195] [client 54.151.227.173:46126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "streetcornerfranchise.com"] [uri "/wp-config.php.zip"] [unique_id "ap4j3IJ7qp_sDaGXv9bzRAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:17:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:17:04.559767 2026] [security2:error] [pid 29778:tid 29778] [client 54.151.227.173:46484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.havenlaneministries.com"] [uri "/.env.zip"] [unique_id "ap4eoG_lLIRTdoVKAFqQ8wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 01:35:07
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:49:46
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:49:39.652617 2026] [security2:error] [pid 12636:tid 12636] [client 54.151.227.173:48262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.citizensforsanity.com"] [uri "/wp-config.php.zip"] [unique_id "ap3uAw1jMPFvpusaHKEPhwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:45:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:45:00.543922 2026] [security2:error] [pid 24515:tid 24515] [client 54.151.227.173:45650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.henhousebbq.com"] [uri "/wp-config.php.zip"] [unique_id "ap3e3IYrqSTNUQYNuN3lzQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-06 20:56:48
(7 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:54:56
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:54:52.717558 2026] [security2:error] [pid 723293:tid 723293] [client 54.151.227.173:49016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.healthycaregiving.com"] [uri "/.htaccess.zip"] [unique_id "ap3THKIfa5T_z70ki0t5RwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:16:21
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:16:13.816469 2026] [security2:error] [pid 24023:tid 24023] [client 54.151.227.173:57224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.haciendaefrain.com"] [uri "/wp-config.php.zip"] [unique_id "ap3KDfNmdT4pfiWaQpE8zgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-06 20:01:02
(7 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:58:07
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:58:00.177925 2026] [security2:error] [pid 3169:tid 3169] [client 54.151.227.173:49070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mdhi-etq-mail.com"] [uri "/wp-config.php.zip"] [unique_id "ap3FyAUhbcVAX5-90XykAwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-06 19:55:38
(8 hours ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
🇺🇸
Matthew Ping
2026-09-06 19:30:01
(8 hours ago)
Excessive connections (DDoS/flood) blocked by CSF CT_LIMIT on wp1.
DDoS Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 18:43:57
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:43:53.216004 2026] [security2:error] [pid 13570:tid 13570] [client 54.151.227.173:60412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.grancanariaholidays.com"] [uri "/.htaccess.zip"] [unique_id "ap20aWXtA45JIpa-ullsCQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:18:21
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.151.227.173 (ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:18:15.226366 2026] [security2:error] [pid 8351:tid 8351] [client 54.151.227.173:44168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.charmainecruz.com"] [uri "/.htaccess.zip"] [unique_id "ap2uZ_VCLlI03H0YTVuGvgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Mediashaker
2026-09-06 18:06:11
(9 hours ago)
(CT) IP 54.151.227.173 (SG/Singapore/ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com) found ...
show more
(CT) IP 54.151.227.173 (SG/Singapore/ec2-54-151-227-173.ap-southeast-1.compute.amazonaws.com) found to have 843 connections
show less
DDoS Attack