๐บ๐ธ
LSPCCU
2026-09-25 09:07:55
(6 hours ago)
TSEC Honeypot Network report. Threat score: 91/100. Categories: Hacking. Honeypot: galah, h0neytr4p. ...
show more
TSEC Honeypot Network report. Threat score: 91/100. Categories: Hacking. Honeypot: galah, h0neytr4p. Context: 67.20.76.199 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
Hacking
๐ฆ๐บ
Block Rockin' Beats
2026-09-25 06:03:03
(9 hours ago)
Scanning for exploitable scripts
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 23:10:10
(2 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 67.20.76.199 - - [23/Sep/2026:01:10:09 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 457 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:34:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:34:38.790492 2026] [security2:error] [pid 11747:tid 11747] [client 67.20.76.199:41524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "warshaw1.com"] [uri "/wp-config.php.bak"] [unique_id "arMCftWMe8YINqEo3RoYWwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:40:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:40:04.219072 2026] [security2:error] [pid 13476:tid 13476] [client 67.20.76.199:31762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "recorplast.com"] [uri "/wp-config.php.bak"] [unique_id "arLnpO9JGQtw1wJNMK4-0wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:45:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:45:17.881312 2026] [security2:error] [pid 25707:tid 25707] [client 67.20.76.199:48818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beachweddinginvites.com"] [uri "/wp-config.php.bak"] [unique_id "arLazdNaMTH7-4qAaP0pKAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:27:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:27:23.429578 2026] [security2:error] [pid 24643:tid 24643] [client 67.20.76.199:14874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.exhaustthelimits.org"] [uri "/wp-config.php.bak"] [unique_id "arLWmxxt7lfpTXrOvMzWAgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:50:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:50:21.993032 2026] [security2:error] [pid 30088:tid 30088] [client 67.20.76.199:54644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rememberingemily.com"] [uri "/wp-config.php.bak"] [unique_id "arLN7QS-zyTiqb0s-9q2RwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:11:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:11:09.999250 2026] [security2:error] [pid 25584:tid 25584] [client 67.20.76.199:39694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modele18.com"] [uri "/wp-config.php.bak"] [unique_id "arLEvRVIPx7CeLH--wjatgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:04:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:03:55.899001 2026] [security2:error] [pid 17731:tid 17731] [client 67.20.76.199:32972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathewyoung.com"] [uri "/wp-config.php.bak"] [unique_id "arK0-_ms9vh0T1BFRe4BnAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:30:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:30:26.456898 2026] [security2:error] [pid 29800:tid 29800] [client 67.20.76.199:27652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ronelgas.com"] [uri "/wp-config.php.bak"] [unique_id "arKC8gjxkxHhzJQ_XBSjpQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:33:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:33:13.870132 2026] [security2:error] [pid 680640:tid 680640] [client 67.20.76.199:42646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sublimetiles.com"] [uri "/wp-config.php.bak"] [unique_id "arJ1iQrFza16wCAsYjRKJAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:50:47
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 67.20.76.199 (host2031.hostmonster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:50:39.583302 2026] [security2:error] [pid 11459:tid 11459] [client 67.20.76.199:40762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "k-and-l-contractors.com"] [uri "/wp-config.php.bak"] [unique_id "arJrjz9mX-ksXvMCmVVngAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-03-01 05:35:15
(6 months ago)
10 attempts against mh-pma-try-ban on kale
Web App Attack
๐ณ๐ฑ
Roderic
2026-02-01 07:17:59
(7 months ago)
(apache_scanners-2) Failed apache-scanners trigger with match [redacted])
Port Scan