๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
windowsforum
2026-02-14 13:32:53
(3 months ago)
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, username=Alejandrin
Web Spam
Bad Web Bot
๐ฉ๐ช
stinpriza
2026-02-03 01:03:39
(4 months ago)
Web App Attack
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-26 09:15:34
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ง๐ช
DrLex0
2026-01-10 01:06:05
(5 months ago)
Suspect single hit only to guestbook page prohibited by robots.txt, from multiple IPs in the same ra ...
show more
Suspect single hit only to guestbook page prohibited by robots.txt, from multiple IPs in the same ranges owned by DREI-K-TECH-GMBH, DE
show less
Bad Web Bot
๐ณ๐ฑ
Mangelot Hosting
2026-01-04 00:09:21
(5 months ago)
(wp_config_access) srv102 Access wp-config.php 193.56.28.223 (US/United States/-): 1 in the last 360 ...
show more
(wp_config_access) srv102 Access wp-config.php 193.56.28.223 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
mnsf
2025-12-30 11:05:16
(5 months ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:06
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-12-11 09:19:10
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 07:01:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.223 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:01:32.228080 2025] [security2:error] [pid 6195:tid 6195] [client 193.56.28.223:59123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "castagnino.com"] [uri "/.git/HEAD"] [unique_id "aS6OzG85x9eb4BnkVaSdlQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:19:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.223 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:19:37.916929 2025] [security2:error] [pid 5131:tid 5131] [client 193.56.28.223:37379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digitaltom.com"] [uri "/.svn/wc.db"] [unique_id "aS526QlxePU_3zp-iyhSmAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2025-12-02 00:56:14
(6 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 10:12:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.223 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:12:35.728613 2025] [security2:error] [pid 3793064:tid 3793090] [client 193.56.28.223:20283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedpoliticalscientist.com.aafm.us"] [uri "/.svn/wc.db"] [unique_id "aSbSk8ImjdfZpXBWNqQWhwAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-26 09:43:43
(6 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:39:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.223 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:39:38.082577 2025] [security2:error] [pid 2597135:tid 2597135] [client 193.56.28.223:57087] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aholsniffsglue.com"] [uri "/.svn/wc.db"] [unique_id "aSa8ys4TLw6Vu0Q9fccefwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack