๐บ๐ธ
TPI-Abuse
2026-09-22 17:18:07
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:18:00.157091 2026] [security2:error] [pid 26718:tid 26718] [client 89.46.108.130:32702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ladylilacfarm.com"] [uri "/wp-config.php.bak"] [unique_id "arK4SFA7JUOxK1-RJR0BjgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:41:01
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:40:57.478332 2026] [security2:error] [pid 28569:tid 28588] [client 89.46.108.130:31454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thetooheys.com"] [uri "/patzer//wp-config.php.bak"] [unique_id "arKvmZ68ubmIqLgR_mKRdAAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:04:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:04:24.513826 2026] [security2:error] [pid 15676:tid 15676] [client 89.46.108.130:33778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monopolimusic.com"] [uri "/wp-config.php.bak"] [unique_id "arKnCEqGPdJEEfrBKL0diwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:23:48
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:23:44.488967 2026] [security2:error] [pid 9457:tid 9457] [client 89.46.108.130:24880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proprocessor.com"] [uri "/wp-config.php.bak"] [unique_id "arKPcBgYh2rAI3UB7vz1rwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:07:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:07:52.461354 2026] [security2:error] [pid 32356:tid 32356] [client 89.46.108.130:31228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kmelson.com"] [uri "/wp-config.php.bak"] [unique_id "arKLuJnUUnZOFRCutdeoRgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:29:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:29:07.795579 2026] [security2:error] [pid 11018:tid 11018] [client 89.46.108.130:43980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingstoneproperties.com"] [uri "/wp-config.php.bak"] [unique_id "arKCo6CtKBaSAmj4SDc2LgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:50:08
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.108.130 (host130-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:50:01.733478 2026] [security2:error] [pid 12900:tid 12900] [client 89.46.108.130:38792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airintakesonline.com"] [uri "/.env"] [unique_id "arII-cCb_xQJRbSYwIKK9QAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 19:32:53
(21 hours ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: /seed.txt | 2026-09-21 19:32 UTC
show less
Bad Web Bot
Anonymous
2025-11-21 01:02:48
(10 months ago)
Web attack
Bad Web Bot
Web App Attack
๐บ๐ธ
Zandro
2025-08-30 00:10:00
(1 year ago)
ranged TCP flood attack
DDoS Attack
๐บ๐ธ
anon333
2025-08-29 16:36:21
(1 year ago)
Hacker syslog review 1756485381
Hacking
๐ฉ๐ช
Ba-Yu
2025-05-04 18:39:30
(1 year ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
Anonymous
2025-05-04 09:14:50
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
Rip
2025-05-03 13:37:11
(1 year ago)
Automated reconnaissance attempt targeting restricted or sensitive paths.
...
Brute-Force
Web App Attack
Anonymous
2025-05-03 08:50:30
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH