๐ฉ๐ช
BlueWire Hosting
2026-09-25 07:14:13
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐น๐ท
ycoskun41
2026-09-22 23:34:37
(3 days ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:36:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:36:07.684340 2026] [security2:error] [pid 27262:tid 27262] [client 89.161.193.170:55065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pembrokefinance.com"] [uri "/wp-config.php.bak"] [unique_id "arLmt59MFKvwSVNbatZ3PAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Bay13
2026-09-22 20:12:30
(3 days ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:43:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:43:46.420119 2026] [security2:error] [pid 15811:tid 15914] [client 89.161.193.170:53807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.siriuspharmaceuticals.com"] [uri "/wp-config.php.bak"] [unique_id "arK-UqFoCY7CHIB-ZjDwzwAAAgU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:15:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:15:02.574051 2026] [security2:error] [pid 8206:tid 8206] [client 89.161.193.170:49773] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "totho.com"] [uri "/wp-config.php.bak"] [unique_id "arK3liEGogKPfmEVw0e7ugAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 03:52:42
(4 days ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env | 2026-09-22 03:52 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
geot
2025-05-02 12:37:08
(1 year ago)
GET /wp-config.php.org HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-01 17:56:11
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 01 13:56:05.974018 2025] [security2:error] [pid 617351:tid 617351] [client 89.161.193.170:42359] [client 89.161.193.170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.texaslawman.net"] [uri "/wp-config.php.org"] [unique_id "aBO1tbZdSmWy_KC3Do9vHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2025-05-01 06:25:00
(1 year ago)
Malicious activity detected: URL probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-01 03:46:41
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 23:46:35.522971 2025] [security2:error] [pid 39027:tid 39027] [client 89.161.193.170:54249] [client 89.161.193.170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gogitzit.com"] [uri "/wp-config.php~"] [unique_id "aBLumxi_mm82RxNvtlSy9gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2025-04-30 23:04:00
(1 year ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-30 19:04:30
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 15:04:24.787620 2025] [security2:error] [pid 2807402:tid 2807402] [client 89.161.193.170:45719] [client 89.161.193.170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bestnebraskadetective.com"] [uri "/wp-config.phpold"] [unique_id "aBJ0OMM8aFwnkU8RszeMcAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-30 15:18:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 89.161.193.170 (cloudserver037000.home.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 11:18:05.061677 2025] [security2:error] [pid 30890:tid 30890] [client 89.161.193.170:55583] [client 89.161.193.170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seskalee.com"] [uri "/wp-config.phpold"] [unique_id "aBI_LYTWcf72SIcymQQ5DgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2025-04-30 10:09:24
(1 year ago)
MYH: Web Attack GET /wp-config.phpold
Web Spam
Hacking
Bad Web Bot
Web App Attack