Anonymous
2026-09-25 10:35:02
(2 weeks ago)
suspicious request in access.log
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-25 06:11:21
(2 weeks ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:58:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.87.227 (infong-eu230.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.87.227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:58:20.229250 2026] [security2:error] [pid 21784:tid 21784] [client 82.165.87.227:56746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stinkingpink.com"] [uri "/wp-config.php.bak"] [unique_id "arMIDMvp0xZLl2q0bYXX5gAAAG8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:15:11
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.87.227 (infong-eu230.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.87.227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:15:04.118790 2026] [security2:error] [pid 7762:tid 7762] [client 82.165.87.227:35220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travel-pix.com"] [uri "/wp-config.php.bak"] [unique_id "arLhyHs6i231AFR4MtgD0gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:50:45
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.87.227 (infong-eu230.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.87.227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:50:41.372049 2026] [security2:error] [pid 29339:tid 29339] [client 82.165.87.227:55736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "majersigns.com"] [uri "/wp-config.php.bak"] [unique_id "arK_8RdR07UabVhgUG-2lAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-22 13:07:58
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 13:07:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 82.165.87.227 (infong-eu230.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.87.227 (infong-eu230.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:07:44.768975 2026] [security2:error] [pid 17035:tid 17035] [client 82.165.87.227:53114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "formationone.com"] [uri "/wp-config.php.bak"] [unique_id "arJ9oEGZ9ezBBrHs0lSZiwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 11:03:27
(2 weeks ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /wp-config.php.bak | 2026-09-22 11:03 UTC
show less
Hacking
Web App Attack
๐ฆ๐บ
weblite
2025-09-21 11:58:13
(1 year ago)
LONG_RUNNING WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-09-20 10:24:33
(1 year ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
stinpriza
2025-09-20 10:21:18
(1 year ago)
Web App Attack
Web App Attack
๐ฉ๐ช
LRob
2025-09-20 04:32:32
(1 year ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ท
Kenshin869
2025-09-16 13:05:00
(1 year ago)
Wordpress unauthorized access attempt
Brute-Force
๐ฉ๐ช
Rey
2025-09-16 08:11:03
(1 year ago)
WordPress xmlrpc.php attack [8okr34gr]
Web App Attack
๐ฉ๐ช
stinpriza
2025-09-16 03:44:57
(1 year ago)
Web App Attack
Web App Attack