πΊπΈ
TPI-Abuse
2026-09-25 10:29:44
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:29:38.560839 2026] [security2:error] [pid 30290:tid 30290] [client 93.157.102.241:51724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agupgrade.net"] [uri "/.env"] [unique_id "arZNEmOGVvb7MrkJ55zPFwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-09-25 10:05:04
(4 days ago)
Abuse Detected (9)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-25 09:23:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 05:23:19.247118 2026] [security2:error] [pid 28275:tid 28275] [client 93.157.102.241:44690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geauxcowboys.com"] [uri "/.env"] [unique_id "arY9h0H6MEFdqYtlvUyMPgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 22:50:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:50:31.500747 2026] [security2:error] [pid 4237:tid 4237] [client 93.157.102.241:40356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestrealtors.com"] [uri "/wp-config.php.bak"] [unique_id "arMGN4QWUh8uZO7805yF1AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 21:32:10
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:32:04.031446 2026] [security2:error] [pid 21610:tid 21610] [client 93.157.102.241:38490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nunsunveiled.com"] [uri "/wp-config.php.bak"] [unique_id "arLz1CxJXyQxyE-7jfKU5AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 19:16:12
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:16:07.109019 2026] [security2:error] [pid 5740:tid 5740] [client 93.157.102.241:37434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grollman.com"] [uri "/wp-config.php.bak"] [unique_id "arLT98_Qo7P6tSHqGLQ40gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 17:49:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:49:29.796564 2026] [security2:error] [pid 25369:tid 25369] [client 93.157.102.241:53648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chicagowca.com"] [uri "/wp-config.php.bak"] [unique_id "arK_qTMsMfaQtGXUFlgDmwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 16:43:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:43:38.165165 2026] [security2:error] [pid 10836:tid 10836] [client 93.157.102.241:41456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horizontravelgroup.com"] [uri "/wp-config.php.bak"] [unique_id "arKwOlvQZa9WM_RYFWCDKwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 15:22:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:22:50.057192 2026] [security2:error] [pid 31574:tid 31574] [client 93.157.102.241:44282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "customweddingnapkins.com"] [uri "/wp-config.php.bak"] [unique_id "arKdSrKqx0W4oFKWG8yLRgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 13:50:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:50:01.444061 2026] [security2:error] [pid 13716:tid 13751] [client 93.157.102.241:38882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forrestwozniak.com"] [uri "/wp-config.php.bak"] [unique_id "arKHiaJdpEbRpM-GHp8S-AAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-22 12:50:20
(1 week ago)
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 93.157.102.241 - - [22/Sep/2026:14:49:58 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 162 "-" "-"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 12:09:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:09:15.886110 2026] [security2:error] [pid 394:tid 394] [client 93.157.102.241:34428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marianozaro.com"] [uri "/wp-config.php.bak"] [unique_id "arJv6zgAlHonNQV2D05OjgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 09:01:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks ...
show more
(mod_security) mod_security (id:210492) triggered by 93.157.102.241 (www-cl-8.cyberadmin.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:00:57.779683 2026] [security2:error] [pid 3579:tid 3579] [client 93.157.102.241:52760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tanandteh.com"] [uri "/wp-config.php.bak"] [unique_id "arJDyVB2ML19cnPvNXkpUwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-09-04 10:42:20
(3 weeks ago)
101 requests with url.path */debug.log
Brute-Force
Bad Web Bot
πΊπΈ
TAY
2026-09-04 07:35:23
(3 weeks ago)
93.157.102.241 - - [04/Sep/2026:15:35:12 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 54906 "-" "Moz ...
show more
93.157.102.241 - - [04/Sep/2026:15:35:12 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 54906 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
93.157.102.241 - - [04/Sep/2026:15:35:14 +0800] "GET /wp-config.php~ HTTP/1.1" 404 54881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
93.157.102.241 - - [04/Sep/2026:15:35:16 +0800] "GET /wp-config.php.save HTTP/1.1" 404 54907 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
93.157.102.241 - - [04/Sep/2026:15:35:17 +0800] "GET /wp-config.php.old HTTP/1.1" 404 54906 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
93.157.102.241 - - [04/Sep/2026:15:35:18 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 54907 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KH
...
show less
Brute-Force