๐ณ๐ฑ
enpepet
2026-09-25 11:35:40
(4 days ago)
GENERAL: parametres: [url:env=] UA: URL:/.env
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-09-25 08:41:36
(4 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 05:28:36
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 01:28:29.539272 2026] [security2:error] [pid 30869:tid 30869] [client 89.46.108.121:31226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iktonline.org"] [uri "/.env"] [unique_id "arYGfV1Kg3tCF7_X9-AnsQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-09-24 04:04:23
(5 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 12:19:51
(6 days ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-23 07:31:15
(6 days ago)
Suspicious HTTP(s) activity without a user agent provided
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 22:06:23
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:06:16.198523 2026] [security2:error] [pid 22451:tid 22451] [client 89.46.108.121:25720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allmyartprojects.com"] [uri "/exhibitionsfolder/loenefrontpage.html/wp-config.php.bak"] [unique_id "arL72LcZn24-VNORFPSuiQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:46:40
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:46:34.880814 2026] [security2:error] [pid 29891:tid 29891] [client 89.46.108.121:30482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achari.com"] [uri "/wp-config.php.bak"] [unique_id "arL3OoP3ayeROqY-XSEmuwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:31:23
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:31:17.529105 2026] [security2:error] [pid 8320:tid 8320] [client 89.46.108.121:21410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bennoyes.com"] [uri "/wp-config.php.bak"] [unique_id "arLlld5cC-lwsLwQ-jN1LwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:58:08
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:58:03.852898 2026] [security2:error] [pid 16241:tid 16262] [client 89.46.108.121:23370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danfriel.com"] [uri "/wp-config.php.bak"] [unique_id "arLdy75E2sKr39MO73drOQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:12:08
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:12:03.191393 2026] [security2:error] [pid 4318:tid 4318] [client 89.46.108.121:43462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sentientresearch.com"] [uri "/wp-config.php.bak"] [unique_id "arLTAyGsgK5AaPb_2D5ToAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:37:19
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:37:14.979950 2026] [security2:error] [pid 14462:tid 14462] [client 89.46.108.121:40966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barigby.com"] [uri "/wp-config.php.bak"] [unique_id "arLK2jX6kPBAl6-nivNtoQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:10:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:10:21.866756 2026] [security2:error] [pid 28537:tid 28540] [client 89.46.108.121:20202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arotger.com"] [uri "/wp-config.php.bak"] [unique_id "arK2fXhg3T3bGzB6FKWgbAAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:43:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:43:45.555810 2026] [security2:error] [pid 8308:tid 8308] [client 89.46.108.121:35580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "studioyau.com"] [uri "/wp-config.php.bak"] [unique_id "arKwQX_zfiS10bWTn8tEUwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:42:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.121 (host121-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:42:22.700502 2026] [security2:error] [pid 6769:tid 6769] [client 89.46.108.121:20794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bridgital.com"] [uri "/wp-config.php.bak"] [unique_id "arKh3sMpEEXci9jISSItzgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack