🇺🇸
TPI-Abuse
2026-09-13 21:44:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:44:21.137304 2026] [security2:error] [pid 31440:tid 31440] [client 65.49.236.227:57636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.techoutletec.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqcZNUbOdmG2qEp-GEAt3QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 21:27:35
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:27:29.076292 2026] [security2:error] [pid 25918:tid 25918] [client 65.49.236.227:31554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smartradios.info"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqcVQZS3Q-FjaLFmsfrEcwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
[email protected]
2026-09-13 20:38:13
(18 hours ago)
Attack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on www.outindesign.fi (Bl ...
show more
Attack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on www.outindesign.fi (Blocked file upload attempt (MIME-type mismatch)) 65.49.236.227 (JP/Japan/65.49.236.227.16clouds.com): 1 in the last 3600 secs (CF_ENABLE); IP: 65.49.236.227; Ports: *; Direction: 0; Trigger: LF_CUSTOMTRIGGER;
show less
Web App Attack
🇮🇹
VHosting
2026-09-13 18:40:03
(20 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 18:39:49
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 14:39:42.442903 2026] [security2:error] [pid 18043:tid 18043] [client 65.49.236.227:17486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fattoria-rendena.it"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqbt7q_5zdg05fYEEcajXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 18:00:28
(21 hours ago)
(mod_security) mod_security (id:234930) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 i ...
show more
(mod_security) mod_security (id:234930) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 14:00:22.534889 2026] [security2:error] [pid 12236:tid 12236] [client 65.49.236.227:60922] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.clipper1970.com.jimgrenier.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.clipper1970.com.jimgrenier.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aqbktoAHiLPNTsDakX9B-wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-13 17:38:00
(21 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-13 17:36:50
(21 hours ago)
(mod_security) mod_security (id:234930) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 i ...
show more
(mod_security) mod_security (id:234930) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 13:36:42.049270 2026] [security2:error] [pid 30268:tid 30268] [client 65.49.236.227:10762] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.bitcoinsubscribers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.bitcoinsubscribers.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aqbfKp5hSbuE-p0EB8ZDGAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-13 17:17:05
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 17:33:14
(1 month ago)
(mod_security) mod_security (id:217200) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 i ...
show more
(mod_security) mod_security (id:217200) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 13:33:06.388368 2026] [security2:error] [pid 2920905:tid 2920905] [client 65.49.236.227:38910] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||www.techoutletec.com|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.techoutletec.com"] [uri "/"] [unique_id "amZE0hHgNxbxAMPxCoj9FQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 17:08:44
(1 month ago)
(mod_security) mod_security (id:217200) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 i ...
show more
(mod_security) mod_security (id:217200) triggered by 65.49.236.227 (65.49.236.227.16clouds.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 13:08:40.037957 2026] [security2:error] [pid 2020932:tid 2020932] [client 65.49.236.227:16000] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||www.timetemple.org|F|2"] [data "/"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.timetemple.org"] [uri "/"] [unique_id "amY_GL9xPz-JYUUy8rAw2QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack