Anonymous
2026-09-22 23:10:00
(1 day ago)
[web.zebs.ch] httpd-config-scan: sites=www.asiqual.com; logs=/var/log/httpd/domains/asiqual.com.log; ...
show more
[web.zebs.ch] httpd-config-scan: sites=www.asiqual.com; logs=/var/log/httpd/domains/asiqual.com.log; samples=/wp-config.php.bak
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:42:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:42:48.549233 2026] [security2:error] [pid 2021:tid 2021] [client 74.208.56.180:57650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waycoradio.com"] [uri "/wp-config.php.bak"] [unique_id "arLMKAdZEZFa8NE_mN0CQwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:44:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:44:01.840556 2026] [security2:error] [pid 623321:tid 623321] [client 74.208.56.180:47490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naomicotten.com"] [uri "/wp-config.php.bak"] [unique_id "arJqAUA6sZ1p01wfAYERUQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:09:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:09:42.235113 2026] [security2:error] [pid 22558:tid 22558] [client 74.208.56.180:49704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hiscreativedesign.com"] [uri "/wp-config.php.bak"] [unique_id "arJh9g15JQ5Vnj2EWG2iWgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:36:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:36:49.341326 2026] [security2:error] [pid 2680:tid 2680] [client 74.208.56.180:60434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "religiousholidaycards.com"] [uri "/wp-config.php.bak"] [unique_id "arJaQTP9Bs0_de3yabYH2wAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2025-08-25 19:23:27
(1 year ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ฌ๐ง
findlab
2025-08-25 18:10:01
(1 year ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2025-08-17 00:35:58
(1 year ago)
SmallGuard.fr/Prestashop Empty User Agent
Web App Attack
๐ฉ๐ช
iNetWorker
2025-08-13 03:22:03
(1 year ago)
trolling for resource vulnerabilities
Web App Attack
๐จ๐ญ
YF
2025-08-12 16:05:02
(1 year ago)
Attempted access to sensitive files
Web App Attack
Anonymous
2025-07-29 11:33:35
(1 year ago)
Account archive download attempts
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-07-20 06:39:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 20 02:39:04.095368 2025] [security2:error] [pid 8276:tid 8276] [client 74.208.56.180:46978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comitedelafamille.org"] [uri "/wp-config.php_old"] [unique_id "aHyPCIknsiY5nU3mfJB_dAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-18 08:09:19
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 18 04:09:11.584224 2025] [security2:error] [pid 14947:tid 14947] [client 74.208.56.180:34568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grollman.com"] [uri "/wp-config.php1"] [unique_id "aHoBJ9nrnvpGVWHWFoidpQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-18 02:42:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 17 22:42:50.259835 2025] [security2:error] [pid 25341:tid 25341] [client 74.208.56.180:45236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "woosterclassof64.com"] [uri "/wp-config.php1"] [unique_id "aHm0qg7o8eahfmtmyrvOgwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-17 20:11:31
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.56.180 (infong458.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 17 16:11:26.654712 2025] [security2:error] [pid 3195:tid 3195] [client 74.208.56.180:36038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usataxgroup.com"] [uri "/wp-config.php.old"] [unique_id "aHlY7oMSZX5KlHpe02caYQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack