๐บ๐ธ
drewf.ink
2026-09-29 01:22:14
(5 hours ago)
[01:22] Attempted HTTPS access to the GlobalProtect getconfig endpoint (VPN gateway fingerprinting/r ...
show more
[01:22] Attempted HTTPS access to the GlobalProtect getconfig endpoint (VPN gateway fingerprinting/recon)
show less
Web App Attack
๐บ๐ธ
drewf.ink
2026-09-28 22:01:43
(8 hours ago)
[22:01] Attempted HTTPS GlobalProtect login with credentials mcastro:W******1
Web App Attack
๐จ๐ญ
backslash
2026-09-28 04:42:08
(1 day ago)
block ruleset 51D5331ECDCF70C2C6410C0D0EEB5F69B17B5F56
Bad Web Bot
๐บ๐ธ
Kurtbaby
2026-09-25 17:04:00
(3 days ago)
Brute-Force
Port Scan
Hacking
๐บ๐ธ
Ben Schoolland
2026-09-25 01:57:03
(4 days ago)
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legiti ...
show more
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legitimate use.
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-09-09 06:31:20
(2 weeks ago)
Web App Attack
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-21 05:15:41
(2 months ago)
WP Armour Plugin detection
Web Spam
Brute-Force
๐บ๐ธ
mnsf
2026-05-31 20:05:53
(3 months ago)
Abuse Detected (3)
Brute-Force
Web App Attack
Anonymous
2026-03-05 23:32:22
(6 months ago)
Forum/form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-27 19:49:19
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 14:49:12.895128 2025] [security2:error] [pid 23854:tid 23854] [client 193.56.28.19:59833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biomechanicalwars.com"] [uri "/.svn/wc.db"] [unique_id "aSirOPx3-GCyBJ2UgtDTpAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:47:52
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:47:48.956822 2025] [security2:error] [pid 15986:tid 15986] [client 193.56.28.19:39043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.uncle-david.com"] [uri "/.env"] [unique_id "aSaUhOYqJsGZVEvHMTWhaQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:04:18
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:04:11.434460 2025] [security2:error] [pid 30962:tid 30962] [client 193.56.28.19:9403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.youthriskbehaviorbook.com"] [uri "/.svn/wc.db"] [unique_id "aSaKSycs7vGTtMAKx3dtRgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ingroscart.it
2025-11-26 03:36:35
(10 months ago)
(mod_security) mod_security triggered on hostname [redacted] 193.56.28.19 (US/United States/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-11-26 01:21:44
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:21:37.378613 2025] [security2:error] [pid 17544:tid 17550] [client 193.56.28.19:57769] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heworeblack.104ventures.com"] [uri "/.git/HEAD"] [unique_id "aSZWIbdIsiK1k1jqHcTglQAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:48:04
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:47:59.039413 2025] [security2:error] [pid 26959:tid 26959] [client 193.56.28.19:13317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.microkerneltechnologies.com"] [uri "/.env"] [unique_id "aSZOPzhnZHSTleGicTEX1AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack