๐ช๐ธ
alferez
2026-09-03 02:07:47
(2 hours ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 01:11:48
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 21:11:43.204866 2026] [security2:error] [pid 26481:tid 26481] [client 95.38.161.131:50142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modmove.com"] [uri "/wp-config.php.bak"] [unique_id "apjJT0aYYsvMDHb0IiVsLwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 17:32:55
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:32:48.883106 2026] [security2:error] [pid 20652:tid 20652] [client 95.38.161.131:40608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.caddydad.com"] [uri "/wp-config.php.bak"] [unique_id "aphdwE09lvqb3j3gFQGvXAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 17:17:49
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:17:43.884810 2026] [security2:error] [pid 30845:tid 30845] [client 95.38.161.131:42322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trademarkexaminerscom.karenbernsteinlaw.net"] [uri "/wp-config.php.bak"] [unique_id "aphaNyD26OT50wAXNzKgZAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 15:19:17
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:19:12.392151 2026] [security2:error] [pid 9070:tid 9070] [client 95.38.161.131:45972] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "delcano.org"] [uri "/wp-config.php.bak"] [unique_id "apg-cBJZZcDL_4JpbT6CMAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 14:49:20
(13 hours ago)
SOHODE WEBEXPLOIT 95.38.161.131 (95.38.161.131)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 14:40:12
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:40:01.242935 2026] [security2:error] [pid 7984:tid 7984] [client 95.38.161.131:44966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonegym.com"] [uri "/wp-config.php.bak"] [unique_id "apg1QYHJA0d_E8d4PS-86wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-02 13:27:02
(14 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (63, Abuse: 56)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-09-02 13:05:39
(15 hours ago)
Abuse Detected (13)
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-09-02 12:03:28
(16 hours ago)
Aggressive web search of vulnerable pages: /index.php /.env /phpinfo.php /info.php /test.php /backup ...
show more
Aggressive web search of vulnerable pages: /index.php /.env /phpinfo.php /info.php /test.php /backup.sql /backup.sql.gz /backup.zip ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:00:13
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:00:06.464681 2026] [security2:error] [pid 24247:tid 24251] [client 95.38.161.131:48922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.whitecrosslibrary.aafm.us"] [uri "/wp-config.php.bak"] [unique_id "apgPxuhTNxfKbH1CNk34KwAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-02 11:18:05
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 11:12:25
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 07:12:21.111607 2026] [security2:error] [pid 17466:tid 17466] [client 95.38.161.131:58732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drgtek.com.smogsandiego.com"] [uri "/wp-config.php~"] [unique_id "apgElZ9zK4KVmM7lRmInPQAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:50:00
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 95.38.161.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:49:52.121184 2026] [security2:error] [pid 610:tid 610] [client 95.38.161.131:50426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internetnameregistration.com"] [uri "/wp-config.php.bak"] [unique_id "apfHEMeJ9n4xuxpOQTtjnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-02 06:30:02
(21 hours ago)
SYNScan
Web App Attack