🇩🇪
LRob
2026-09-09 04:30:07
(5 days ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-09 04:30 UTC
show less
Bad Web Bot
🇬🇧
consul.to
2026-09-08 20:50:12
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
🇪🇸
scaballe
2026-09-05 22:43:05
(1 week ago)
Web App Attack
Anonymous
2026-09-05 19:39:31
(1 week ago)
Banned by Fail2Ban on server
Web App Attack
🇺🇸
TPI-Abuse
2025-05-07 02:42:13
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 22:42:07.245985 2025] [security2:error] [pid 130474:tid 130474] [client 89.46.104.166:30922] [client 89.46.104.166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lacycustombuilt.com"] [uri "/wp-config.php_"] [unique_id "aBrIf4FN7EtRMoqc09gc6QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2025-05-06 11:39:00
(1 year ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-05 09:28:11
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 05:28:05.568359 2025] [security2:error] [pid 1132202:tid 1132202] [client 89.46.104.166:37724] [client 89.46.104.166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thevenicecafe.com"] [uri "/wp-config.php_bak"] [unique_id "aBiEpQ2P6C5YRAPOztcoOwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2025-05-05 07:09:40
(1 year ago)
89.46.104.166 - - [05/May/2025:10:09:40 +0300] "GET /wp-config.php-old HTTP/1.1" 404 275 "-" "-"
...
Web App Attack
🇺🇦
URAN Publishing Service
2025-05-03 14:21:38
(1 year ago)
89.46.104.166 - - [03/May/2025:17:21:37 +0300] "GET /wp-config.php_old HTTP/1.1" 404 289 "-" "-"
...
Web App Attack
🇺🇸
ipblock.com
2025-05-02 21:55:00
(1 year ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-02 13:34:52
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 02 09:34:46.876688 2025] [security2:error] [pid 1939448:tid 1939448] [client 89.46.104.166:41212] [client 89.46.104.166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stonehillpolicies.myomni.us"] [uri "/wp-config.php~"] [unique_id "aBTJ9mn47t6-I9nl9-iqEAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-01 14:56:19
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 01 10:56:15.546756 2025] [security2:error] [pid 30475:tid 30475] [client 89.46.104.166:30348] [client 89.46.104.166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teenybikinigirls.com"] [uri "/wp-config.php~"] [unique_id "aBOLjxabe5V8N-CJ9XG80AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2025-05-01 10:23:43
(1 year ago)
89.46.104.166 - - [01/May/2025:13:23:41 +0300] "GET /wp-config.php~ HTTP/1.1" 404 287 "-" "-"
...
Web App Attack
🇺🇸
ipblock.com
2025-05-01 00:52:00
(1 year ago)
IPBlock protected site ID [4055-d][s=08].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-04-30 23:18:28
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.104.166 (host166-104-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 19:18:24.254857 2025] [security2:error] [pid 32477:tid 32477] [client 89.46.104.166:23262] [client 89.46.104.166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "borzoi-pedigree.info"] [uri "/wp-config.phpold"] [unique_id "aBKvwFFf_EU8sV4ErC3J8AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack