🇺🇸
TPI-Abuse
2026-09-08 04:07:24
(6 minutes ago)
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:07:17.262589 2026] [security2:error] [pid 32359:tid 32359] [client 95.111.235.240:35446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tttns.com"] [uri "/about-jason//wp-config.php.bak"] [unique_id "ap-J9aRoiEXYriiW8CjbhAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
solution.it
2026-09-08 02:48:12
(1 hour ago)
[Tue Sep 08 04:48:11.853285 2026] [php7:error] [pid 16450:tid 16450] [client 95.111.235.240:37304] s ...
show more
[Tue Sep 08 04:48:11.853285 2026] [php7:error] [pid 16450:tid 16450] [client 95.111.235.240:37304] script '/var/www/html/blog.solution.it/phpinfo.php' not found or unable to stat
show less
Web App Attack
🇧🇪
taivas.nl
2026-09-08 02:32:13
(1 hour ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 01:25:35
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:25:31.398133 2026] [security2:error] [pid 24315:tid 24315] [client 95.111.235.240:47882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shhcenter.com"] [uri "/wp-config.php.save"] [unique_id "ap9kC9YLoBVyGmV_4EBKmAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 21:36:27
(6 hours ago)
Botnet exploit activity
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-07 19:26:12
(8 hours ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:58:14
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:58:08.444137 2026] [security2:error] [pid 10568:tid 10568] [client 95.111.235.240:42082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rockinr.org"] [uri "/wp-config.php.swp"] [unique_id "ap8JQCdebj6G6NHVrdrZDwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 17:55:05
(10 hours ago)
Aggressive web search of vulnerable pages: /info.php /test.php /backup.sql /backup.tar.gz /wp-conten ...
show more
Aggressive web search of vulnerable pages: /info.php /test.php /backup.sql /backup.tar.gz /wp-content/uploads/ /wp-content/backup/ /wp-content/ ...
show less
Web App Attack
🇩🇪
on-com
2026-09-07 16:51:30
(11 hours ago)
URL scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:59:47
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:59:39.802310 2026] [security2:error] [pid 32240:tid 32240] [client 95.111.235.240:39386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ultratecnologia.com.mx"] [uri "/wp-config.php.save"] [unique_id "ap61O-4jvwX0G5GHcboNYgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 11:41:57
(16 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇹🇷
SeczarSecureOps
2026-09-04 09:15:03
(3 days ago)
Auto-blocked by Seczar SecureOps — WAF — SQL Injection Attack Burst (5 events in 10min) at 2026-09-0 ...
show more
Auto-blocked by Seczar SecureOps — WAF — SQL Injection Attack Burst (5 events in 10min) at 2026-09-04 09:15
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:08:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:08:09.223205 2026] [security2:error] [pid 215713:tid 215713] [client 95.111.235.240:40656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troop9weymouth.com"] [uri "/wp-config.php.swp"] [unique_id "app8aR1dpzw_kHdOyl-1DgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
burlacu.org
2026-09-04 07:00:03
(3 days ago)
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 3 attempts ...
show more
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 3 attempts. Blocked automatically.
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 06:57:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 95.111.235.240 (vmi2642261.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:57:04.455592 2026] [security2:error] [pid 2811:tid 2811] [client 95.111.235.240:55380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lasertherapyoc.com"] [uri "/wp-config.php.bak"] [unique_id "apprwAxaMvghwsm1meTGMgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack