🇺🇸
TPI-Abuse
2026-09-08 09:53:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:53:28.539621 2026] [security2:error] [pid 15733:tid 15733] [client 69.197.139.54:50040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgtek.com.smogsandiego.com"] [uri "/wp-config.php~"] [unique_id "ap_bGBGPDWPQ89HjYEfH8wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 09:05:18
(6 hours ago)
FREKISCOM WEBEXPLOIT 69.197.139.54 (69.197.139.54)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:55:39
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:55:33.671413 2026] [security2:error] [pid 13909:tid 13909] [client 69.197.139.54:46408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cayman-islands-real-estate.com"] [uri "/wp-config.php~"] [unique_id "ap95JcEEgMpTJyRaOVArxgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 23:52:59
(15 hours ago)
OKADE WEBEXPLOIT 69.197.139.54 (69.197.139.54)
Web App Attack
🇲🇾
Rizzy
2026-09-07 23:40:55
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-07 23:30:02
(16 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:05:11
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:05:07.459885 2026] [security2:error] [pid 25934:tid 25934] [client 69.197.139.54:41304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lahamradio.com"] [uri "/wp-config.php.save"] [unique_id "ap8K4_CtB8_ovGJbZYlB-QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:48:45
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:48:38.517964 2026] [security2:error] [pid 7550:tid 7550] [client 69.197.139.54:53788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ergocorrect.com"] [uri "/wp-config.php~"] [unique_id "ap8HBnB9gyx7v9Er0S7z8QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 17:36:09
(22 hours ago)
195 requests with url.path *debug.log
194 requests with url.path */debug.log
188 requests with ur ...
show more
195 requests with url.path *debug.log
194 requests with url.path */debug.log
188 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 15:07:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:07:49.921216 2026] [security2:error] [pid 21971:tid 22048] [client 69.197.139.54:33134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.conservativedemocrat.aafm.us"] [uri "/wp-config.php.save"] [unique_id "ap7TRfWbTGVrGESrH1IsuwAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 13:05:16
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:58:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:58:47.887792 2026] [security2:error] [pid 24969:tid 24969] [client 69.197.139.54:41706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ink2wear.com"] [uri "/wp-config.php.save"] [unique_id "ap61B6BwlIrNy4Y6cWcquAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:37:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 69.197.139.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:37:38.981252 2026] [security2:error] [pid 4066:tid 4066] [client 69.197.139.54:41286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.inquisitivequincie.com"] [uri "/wp-config.php~"] [unique_id "ap6iAvxXm3l1CVy1BRABAwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 08:55:02
(1 day ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇨🇭
flaus
2026-09-07 08:24:46
(1 day ago)
Hacking
Bad Web Bot
Web App Attack