๐ฌ๐ง
gigatech
2026-09-22 21:15:04
(6 hours ago)
Webserver Probing
Web App Attack
๐ซ๐ท
COMAITE
2026-09-22 19:03:08
(8 hours ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:45:35
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:45:30.438722 2026] [security2:error] [pid 1165848:tid 1165848] [client 89.46.106.245:43618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "engineeringarts.com"] [uri "/wp-config.php.bak"] [unique_id "arLMyqBVlqD6vpwmZgVkMgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 18:06:53
(9 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /wp-config.php.bak | 2026-09-22 18:06 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:59:49
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:59:44.915581 2026] [security2:error] [pid 3229:tid 3229] [client 89.46.106.245:22090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redlitephotos.com"] [uri "/wp-config.php.bak"] [unique_id "arLCEBTTI74eyRmMEP3IWAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:31:37
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:31:31.974416 2026] [security2:error] [pid 6072:tid 6072] [client 89.46.106.245:47798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vaezi.com"] [uri "/wp-config.php.bak"] [unique_id "arK7c25aKssAHTBnt0iybgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:31:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:31:31.346825 2026] [security2:error] [pid 12505:tid 12505] [client 89.46.106.245:20012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mollins.com"] [uri "/wp-config.php.bak"] [unique_id "arKtY1-PlfWP4zEVizW8vgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:21:48
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:21:40.360652 2026] [security2:error] [pid 25003:tid 25003] [client 89.46.106.245:32118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title45.com"] [uri "/wp-config.php.bak"] [unique_id "arKO9BxUgPnm2kG4o5RBhgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:02:22
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:02:18.207456 2026] [security2:error] [pid 14446:tid 14446] [client 89.46.106.245:28814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ouguergouz.com"] [uri "/wp-config.php.bak"] [unique_id "arKKaqGyPztB0d-vIs-czAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:47:04
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:46:58.762849 2026] [security2:error] [pid 32748:tid 32748] [client 89.46.106.245:40556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dismain.com"] [uri "/wp-config.php.bak"] [unique_id "arKG0kWaWtqtVZwehBuSpQAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:08:50
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:08:45.521333 2026] [security2:error] [pid 31406:tid 31406] [client 89.46.106.245:28384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdhlgroup.com"] [uri "/wp-config.php.bak"] [unique_id "arJ93VZxWwWeGMA9dTeAbwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:22:46
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.106.245 (host245-106-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:22:40.052505 2026] [security2:error] [pid 10767:tid 10767] [client 89.46.106.245:24698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gooch-excavation.com"] [uri "/.env"] [unique_id "arICkH5QgwceD_vt1xGDOwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 20:20:57
(1 day ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐น๐ท
eryilmaz
2026-09-04 02:01:02
(2 weeks ago)
Automated attack blocked by eryilmaz WAF/fail2ban: 1 event(s) [waf.block] in the last 1 days, e.g. / ...
show more
Automated attack blocked by eryilmaz WAF/fail2ban: 1 event(s) [waf.block] in the last 1 days, e.g. /en/xmlrpc.php
show less
Web App Attack
Hacking
๐ซ๐ท
SpaceHost-Server
2026-09-03 22:26:47
(2 weeks ago)
Brute-Force
Web App Attack