🇺🇸
TPI-Abuse
2026-09-08 10:28:36
(56 minutes ago)
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:28:30.705418 2026] [security2:error] [pid 28430:tid 28430] [client 85.239.235.102:49426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southsideaccountingservices.com"] [uri "/wp-config.php.bak"] [unique_id "ap_jTrsYh1WPKQLyvK0I9AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-08 10:17:24
(1 hour ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-09-08 09:48:01
(1 hour ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-08 09:16:16
(2 hours ago)
FREKISCOM WEBEXPLOIT 85.239.235.102 (vmi3471801.contaboserver.net)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:30:59
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:30:55.027204 2026] [security2:error] [pid 11900:tid 11900] [client 85.239.235.102:52062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stoneybluff.com"] [uri "/wp-config.php.bak"] [unique_id "ap_Hv0wCbM1nS6jEvQLW1QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:22:03
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:21:55.727766 2026] [security2:error] [pid 32610:tid 32610] [client 85.239.235.102:52318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vansfanz.rollinchassis.com"] [uri "/wp-config.php.bak"] [unique_id "ap-pgwV2uoGy5ZuSmWDNmQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-09-08 03:55:40
(7 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:28:59
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:28:54.627913 2026] [security2:error] [pid 579:tid 579] [client 85.239.235.102:33996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hierrosbernal.ayudaclic.com"] [uri "/wp-config.php.old"] [unique_id "ap9y5prGymPUPixARW8aLAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 00:46:02
(10 hours ago)
127 requests with url.path */debug.log
127 requests with url.path *debug.log
Brute-Force
Bad Web Bot
🇩🇪
FeG Deutschland
2026-09-07 23:27:16
(11 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 22:28:48
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.235.102 (vmi3471801.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:28:39.402757 2026] [security2:error] [pid 3876:tid 3876] [client 85.239.235.102:57716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fishleadership.org"] [uri "/wp-config.php.bak"] [unique_id "ap86l5pD2foc7teoBTiOhgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 21:25:30
(13 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-07 21:25:21
(13 hours ago)
Aggressive web search of vulnerable pages: /.env /phpinfo.php /info.php /backup.sql /backup.sql.gz / ...
show more
Aggressive web search of vulnerable pages: /.env /phpinfo.php /info.php /backup.sql /backup.sql.gz /backup.zip ...
show less
Web App Attack