๐บ๐ธ
TPI-Abuse
2026-09-25 10:12:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:12:07.813254 2026] [security2:error] [pid 5201:tid 5201] [client 82.165.81.15:55580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffhinkley.com"] [uri "/.env"] [unique_id "arZI9w1_mA57HIcnFoDAigAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 08:03:45
(1 week ago)
[server.tmg.gr] httpd-config-scan: sites=www.add2024.gr; logs=/var/log/httpd/domains/add2024.gr.log; ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.add2024.gr; logs=/var/log/httpd/domains/add2024.gr.log; samples=/.env
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-25 00:39:00
(1 week ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: /bitcoin.txt | 2026-09-25 00:39 UTC
show less
Bad Web Bot
๐ช๐ธ
librebit
2026-09-24 10:46:01
(2 weeks ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 23:48:41
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:48:36.644753 2026] [security2:error] [pid 17199:tid 17231] [client 82.165.81.15:55552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greenconsciencesc.com"] [uri "/wp-config.php.bak"] [unique_id "arMT1L1Pue2a_IP3Qag3QQAAAVc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 21:05:14
(2 weeks ago)
82.165.81.15 - - [22/Sep/2026:23:05:07 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 162 "-" "-"
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:52:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:52:42.749651 2026] [security2:error] [pid 11203:tid 11203] [client 82.165.81.15:50922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ridgecrestrealtors.com"] [uri "/wp-config.php.bak"] [unique_id "arLqmhD2HKR8NdgdNAIEigAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:00:31
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:00:24.395786 2026] [security2:error] [pid 2497:tid 2497] [client 82.165.81.15:35962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "entetanimiento.com"] [uri "/wp-config.php.bak"] [unique_id "arLeWOQ8Mz_NiAaoEiqqWgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:01:14
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:01:07.199701 2026] [security2:error] [pid 17632:tid 17632] [client 82.165.81.15:41994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "technicallydental.com"] [uri "/wp-config.php.bak"] [unique_id "arK0U5JWdXd6UJm3ab9vygAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:02:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:02:50.342333 2026] [security2:error] [pid 932085:tid 932085] [client 82.165.81.15:51944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cactusstarvineyard.com"] [uri "/wp-config.php.bak"] [unique_id "arKmqiHLZXXjVgSSa4aXQAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-09-22 15:52:06
(2 weeks ago)
tcp/80; WordPress config backup access attempt: "GET /wp-config.php.bak" @ 2026-09-22T15:52:06Z [pro ...
show more
tcp/80; WordPress config backup access attempt: "GET /wp-config.php.bak" @ 2026-09-22T15:52:06Z [proxy]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:17:36
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:17:29.608332 2026] [security2:error] [pid 24448:tid 24635] [client 82.165.81.15:34288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supradig.com"] [uri "/wp-config.php.bak"] [unique_id "arKcCe_9QIngvDelSBg1zgAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:20:43
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:20:38.629688 2026] [security2:error] [pid 28657:tid 28657] [client 82.165.81.15:34024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infinityartistsgroup.com"] [uri "/wp-config.php.bak"] [unique_id "arKApkMb-I-_H_i_bB9j2wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-22 11:54:53
(2 weeks ago)
SmallGuard.fr - Forbidden Ext.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 03:28:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.81.15 (infong351.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 23:28:19.867260 2026] [security2:error] [pid 13468:tid 13468] [client 82.165.81.15:56652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gilbertortegajewelry.com"] [uri "/.env"] [unique_id "arH10yFNphXColO1f8hxewAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack