🇳🇱
JaRoNL
2026-09-12 01:05:14
(1 hour ago)
54.80.177.72 - - [12/Sep/2026:03:05:12 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 23792 "-" "Mozil ...
show more
54.80.177.72 - - [12/Sep/2026:03:05:12 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 23792 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 00:49:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:49:23.642229 2026] [security2:error] [pid 23459:tid 23459] [client 54.80.177.72:33276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modalsoftware.mainstreetofficesuites.com"] [uri "/wp-config.php.bak"] [unique_id "aqShk6_SQYYwJKVevdRWnwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
JaRoNL
2026-09-12 00:29:21
(2 hours ago)
54.80.177.72 - - [12/Sep/2026:02:29:20 +0200] "GET /wp-config.php.bak HTTP/1.1" 302 7402 "-" "Mozill ...
show more
54.80.177.72 - - [12/Sep/2026:02:29:20 +0200] "GET /wp-config.php.bak HTTP/1.1" 302 7402 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 23:41:33
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 19:41:27.793477 2026] [security2:error] [pid 8521:tid 8524] [client 54.80.177.72:41800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nimbll.com"] [uri "/wp-config.php.bak"] [unique_id "aqSRpxhrCTUMD522hIeAKwAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-11 23:27:49
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 22:51:40
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 18:51:34.891554 2026] [security2:error] [pid 9964:tid 9964] [client 54.80.177.72:38270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staben.vccemail.net"] [uri "/wp-config.php~"] [unique_id "aqSF9mNAue_Uqy3Urvtd9wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 22:24:05
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 18:24:01.582138 2026] [security2:error] [pid 3238:tid 3238] [client 54.80.177.72:53036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsenalfordemocracy.com"] [uri "/wp-config.php.save"] [unique_id "aqR_gX8xa1yBMz3pPN0HSwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-11 21:56:56
(4 hours ago)
214 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 21:50:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 17:50:20.914358 2026] [security2:error] [pid 7111:tid 7111] [client 54.80.177.72:44942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.english.art.mavikalem.org"] [uri "/wp-config.php.bak"] [unique_id "aqR3nDDnfaEDesHd5aBaAAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-11 21:37:57
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (US/United States/ec2-54-80-177-72 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (US/United States/ec2-54-80-177-72.compute-1.amazonaws.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 21:15:49
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 17:15:41.521976 2026] [security2:error] [pid 30323:tid 30323] [client 54.80.177.72:42634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theamarals.com"] [uri "/wp-config.php~"] [unique_id "aqRvfVnszmxrtcp6x7rV0wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
penjaga BRIN
2026-09-11 21:02:36
(5 hours ago)
Suspicious malicious activity
Hacking
🇧🇪
taivas.nl
2026-09-11 20:02:14
(6 hours ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 20:00:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.80.177.72 (ec2-54-80-177-72.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 16:00:27.942779 2026] [security2:error] [pid 3180:tid 3180] [client 54.80.177.72:49348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brazilianbottom.com"] [uri "/wp-config.php.bak"] [unique_id "aqRd22V9gG561bDXCqgbyQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-11 19:40:03
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack