๐ช๐ธ
librebit
2026-07-14 03:05:19
(1 month ago)
Brute force
Brute-Force
๐ฉ๐ช
Admins@FBN
2026-07-14 01:21:51
(1 month ago)
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-04 23:45:52
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 185.209.196.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 185.209.196.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 19:45:47.998361 2026] [security2:error] [pid 32180:tid 32180] [client 185.209.196.217:49464] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.209.196.217 (+1 hits since last alert)|williamfitzsimmons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "williamfitzsimmons.com"] [uri "/xmlrpc.php"] [unique_id "akmbKywKx0_U2RzEk3RDpgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-04 21:50:21
(2 months ago)
(wordpress) Failed wordpress login from 185.209.196.217 (DE/Germany/-)
Brute-Force
๐บ๐ธ
factor1
2026-07-04 21:29:28
(2 months ago)
Fail2ban at saturn Reports Abuse.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 19:59:57
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 185.209.196.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 185.209.196.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 15:59:54.027395 2026] [security2:error] [pid 30411:tid 30411] [client 185.209.196.217:49562] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.209.196.217 (+1 hits since last alert)|iconconstructors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iconconstructors.com"] [uri "/xmlrpc.php"] [unique_id "aklmOlrufJGL5hv1xKU_rwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-05-28 21:45:18
(3 months ago)
(xmlrpc_405) XMLRPC-Bot 405 185.209.196.217 (DE/Germany/-)
Hacking
๐ณ๐ฑ
Site.eu
2026-05-05 19:25:25
(4 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
FeG Deutschland
2026-04-29 10:37:25
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-28 07:13:34
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 28
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 15:01:13
(4 months ago)
(mod_security) mod_security (id:210831) triggered by 185.209.196.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 185.209.196.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 11:01:09.846044 2026] [security2:error] [pid 11447:tid 11447] [client 185.209.196.217:40708] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.oualierealty.com|F|4"] [data "grub-client"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.oualierealty.com"] [uri "/index.php"] [unique_id "aeo0NT2j_eIjera67951oQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-04-22 22:18:57
(4 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ฉ๐ช
conseilgouz
2026-04-13 07:08:58
(4 months ago)
mae-12 : Block return, carriage return, ... characters=>/index.php/presentation?catid=2%3Anon-catego ...
show more
mae-12 : Block return, carriage return, ... characters=>/index.php/presentation?catid=2%3Anon-categorise&id=7%3Amentions-legales&view=article%27(')
show less
Hacking
๐ฎ๐น
alessio loto
2026-04-12 13:47:22
(5 months ago)
WAF Detection: Security_Scanner_Blocked (Abusive IP). AI Confirmed Attack Payload.
Bad Web Bot
๐ซ๐ท
โจ
2026-04-09 01:52:15
(5 months ago)
Domain : adventurephotographs.com
Rule : DangerQueryString
2026-04-09 01:50:26 ***hidden-privacy***4 ...
show more
Domain : adventurephotographs.com
Rule : DangerQueryString
2026-04-09 01:50:26 ***hidden-privacy***48 GET /karakoram/skardu/k2_motel/index.aspx c=1' 80 - 185.209.196.217 HTTP/1.1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.154 Safari/537.36 OPR/20.0.1387.91 - www.adventurephotographs.com 302 0 0 592 260 62 - -
show less
Web App Attack