๐บ๐ธ
TPI-Abuse
2026-09-23 00:21:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:20:58.953296 2026] [security2:error] [pid 17876:tid 17876] [client 89.46.106.242:43832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "independentmusicconference.com"] [uri "/wp-config.php.bak"] [unique_id "arMbapXeEqDxl1O08w17PgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 23:01:16
(1 day ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /wp-config.php.bak | 2026-09-22 23:01 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:30:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:30:31.645601 2026] [security2:error] [pid 29691:tid 29691] [client 89.46.106.242:24946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "addocc.com"] [uri "/wp-config.php.bak"] [unique_id "arLzd1XDbmIKXZRg30_cPgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:38:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:38:46.136119 2026] [security2:error] [pid 17330:tid 17330] [client 89.46.106.242:30364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mrzradio.org"] [uri "/wp-config.php.bak"] [unique_id "arLnVr6T7vyzO7SUYRU0TQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-22 19:57:41
(1 day ago)
89.46.106.242 - - [22/Sep/2026:21:57:40 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 546 "-" "-"
89. ...
show more
89.46.106.242 - - [22/Sep/2026:21:57:40 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 546 "-" "-"
89.46.106.242 - - [22/Sep/2026:21:57:40 +0200] "GET /wp-config.php.bak HTTP/2.0" 403 393 "-" "-"
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 18:47:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:47:25.678843 2026] [security2:error] [pid 15282:tid 15282] [client 89.46.106.242:47188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drstiso.com"] [uri "/wp-config.php.bak"] [unique_id "arLNPWzN6WmRjk2jIeRi-wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:23:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:23:37.665081 2026] [security2:error] [pid 25080:tid 25080] [client 89.46.106.242:44732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dhappraisalservices.com"] [uri "/wp-config.php.bak"] [unique_id "arLHqU8KYauDnWhCMpkVggAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 17:51:12
(1 day ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 89.46.106.242 - - [22/Sep/2026:19:51:11 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 449 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:25:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:25:35.336786 2026] [security2:error] [pid 963459:tid 963459] [client 89.46.106.242:22266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eastsidenotary.com"] [uri "/wp-config.php.bak"] [unique_id "arKr_6Ml5qijx_6OUarCFQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:00:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:00:21.347297 2026] [security2:error] [pid 24753:tid 24753] [client 89.46.106.242:33484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mikeziegler.com"] [uri "/wp-config.php.bak"] [unique_id "arKmFWAs5qWu4yuoKBfQEgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:09:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:09:18.772107 2026] [security2:error] [pid 29852:tid 29852] [client 89.46.106.242:42906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mthompson-business-services.com"] [uri "/wp-config.php.bak"] [unique_id "arKMDvVXdQvdqX2hlPzAVQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:45:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:45:11.590458 2026] [security2:error] [pid 8621:tid 8621] [client 89.46.106.242:39700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "encoreporchfest.info"] [uri "/wp-config.php.bak"] [unique_id "arKGZ2TnCrCc_-T0Dg1R1QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rip
2026-09-22 12:29:12
(1 day ago)
Restricted File Access Attempts
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:41:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:41:29.118974 2026] [security2:error] [pid 3803:tid 3803] [client 89.46.106.242:37954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edmontonwaterjet.com"] [uri "/wp-config.php.bak"] [unique_id "arJpaYi1Hfy4P6rhWWfkJQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:38:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.242 (host242-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:38:02.064126 2026] [security2:error] [pid 15394:tid 15394] [client 89.46.106.242:30736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carbtestingidaho.com"] [uri "/.env"] [unique_id "arIGKuf2on8Q-SDW2H8rCgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack