🇺🇸
TAY
2026-09-05 11:24:27
(37 minutes ago)
80.74.155.60 - - [05/Sep/2026:19:24:21 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 34565 "-" "Mozil ...
show more
80.74.155.60 - - [05/Sep/2026:19:24:21 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 34565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
80.74.155.60 - - [05/Sep/2026:19:24:22 +0800] "GET /wp-config.php~ HTTP/1.1" 404 34565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
80.74.155.60 - - [05/Sep/2026:19:24:23 +0800] "GET /wp-config.php.save HTTP/1.1" 404 34565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
80.74.155.60 - - [05/Sep/2026:19:24:24 +0800] "GET /wp-config.php.old HTTP/1.1" 404 34565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
80.74.155.60 - - [05/Sep/2026:19:24:25 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 34565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 11:23:11
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 07:23:07.055475 2026] [security2:error] [pid 23904:tid 23904] [client 80.74.155.60:31988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsenalfordemocracy.com"] [uri "/wp-config.php.save"] [unique_id "apv7m5GnEqyLg--mCBbqGQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 11:10:56
(51 minutes ago)
FPROCO WEBEXPLOIT 80.74.155.60 (torn.sui-inter.net)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 10:47:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 06:47:21.627388 2026] [security2:error] [pid 13676:tid 13676] [client 80.74.155.60:25514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hierrosbernal.ayudaclic.com"] [uri "/wp-config.php.bak"] [unique_id "apvzOSjm8ofgvl-lV88IUQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
antlac1
2026-09-05 09:09:11
(2 hours ago)
crowdsecurity/http-wordpress_wpconfig
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 09:04:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 05:04:32.575051 2026] [security2:error] [pid 31121:tid 31121] [client 80.74.155.60:10024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aimer.es.aticom.es"] [uri "/wp-config.php.bak"] [unique_id "apvbIEFWAoEYS1UYoh94MwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-05 08:28:44
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 08:09:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 04:09:40.949581 2026] [security2:error] [pid 25288:tid 25288] [client 80.74.155.60:65288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nihlabs.org"] [uri "/wp-config.php.save"] [unique_id "apvORBmvV0TWVq8merHmqAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 07:51:55
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-05 07:40:01
(4 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 07:38:40
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 80.74.155.60 (torn.sui-inter.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 03:38:33.455106 2026] [security2:error] [pid 6417:tid 6424] [client 80.74.155.60:37914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.whitecrosslibrary.aafm.us"] [uri "/wp-config.php.txt"] [unique_id "apvG-VWSa7uM2gWj0nVXlAAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 07:38:32
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
dot.mg
2026-09-04 08:53:06
(1 day ago)
Bad behaviour
Web Spam
🇹🇷
SeczarSecureOps
2026-09-04 08:42:01
(1 day ago)
Auto-blocked by Seczar SecureOps — WAF — SQL Injection Attack Burst (8 events in 10min) at 2026-09-0 ...
show more
Auto-blocked by Seczar SecureOps — WAF — SQL Injection Attack Burst (8 events in 10min) at 2026-09-04 08:42
show less
Web App Attack
🇧🇪
cmbplf
2026-09-04 08:31:49
(1 day ago)
463 requests with url.path *.php.bak
157 requests with url.path */debug.log
157 requests with url ...
show more
463 requests with url.path *.php.bak
157 requests with url.path */debug.log
157 requests with url.path *debug.log
show less
Brute-Force
Bad Web Bot