๐ฌ๐ท
setupgr
2026-10-02 22:52:30
(23 hours ago)
(wplogin_block) Blocked WP-Login Access Attempt 209.50.160.158 (US/United States/Virginia/Ashburn/-/ ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 209.50.160.158 (US/United States/Virginia/Ashburn/-/[AS200373 3xK Tech GmbH]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 209.50.160.158 - - [03/Oct/2026:01:45:05 +0300] "GET /wp-login.php HTTP/1.1" 200 9723 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
show less
Port Scan
๐จ๐ฟ
lp
2026-09-22 18:21:46
(1 week ago)
Unauthorized VPN login attempts: 21 attempts were recorded from 209.50.160.158
2026-09-22T19:00:55+0 ...
show more
Unauthorized VPN login attempts: 21 attempts were recorded from 209.50.160.158
2026-09-22T19:00:55+02:00 vpn Access-Reject 'usertemp' station: 209.50.160.158 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-22T19:03:07+02:00 vpn Access-Reject 'megu' station: 209.50.160.158 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-22T19:05:11+02:00 vpn Access-Reject 'administrator' station: 209.50.160.158 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-22T19:07:12+02:00 vpn Access-Reject 'user81' station: 209.50.160.158 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-22T19:09:14+02:00 vpn Access-Reject 'jo' station: 209.50.160.158 auth-type: - realm: vse.cz nas:
show less
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-14 21:01:29
(2 weeks ago)
[15/Sep/2026:00:01:28 +0300] -- 209.50.160.158 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[15/Sep/2026:00:01:28 +0300] -- 209.50.160.158 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/ HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-08-02 02:05:19
(2 months ago)
Web App Attack
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 months ago)
Apache probe; attempts=17; exact paths: /xmlrpc.php
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-25 23:19:35
(2 months ago)
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 209.50.160.158 - - [26/Jul/2026:02:19:26 +0300] "G ...
show more
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 209.50.160.158 - - [26/Jul/2026:02:19:26 +0300] "GET /wp-login.php HTTP/2.0" 403 24055 "http://avaxgr.eu/wp-login.php" "Mozilla/5.0"
show less
Web App Attack
๐ซ๐ท
Sklurk
2026-07-17 03:07:45
(2 months ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-06-20 00:21:47
(3 months ago)
Web App Attack
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(6 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 07:51:21
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 02:51:16.260970 2026] [security2:error] [pid 25969:tid 25969] [client 209.50.160.158:23273] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cobbwebb.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cobbwebb.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZgSdDnbmMc_F7cBlI3q7gAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-02-10 06:06:28
(7 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /new/.git/con ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /new/.git/config
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:13:04
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:12:58.091110 2026] [security2:error] [pid 24206:tid 24206] [client 209.50.160.158:44507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinnen.org"] [uri "/admin/.git/config"] [unique_id "aYqiOt2vPmX7hR4FxmRJlQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:46:55
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:46:50.257918 2026] [security2:error] [pid 16011:tid 16011] [client 209.50.160.158:37891] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madisonjazzorchestra.com"] [uri "/admin/.git/config"] [unique_id "aYqcGpI1xk5UEmh9gYa0-AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:18:06
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:18:00.311056 2026] [security2:error] [pid 31094:tid 31103] [client 209.50.160.158:58653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killyourattitude.com"] [uri "/.env.save"] [unique_id "aYqVWO9YRKhmU5Oqp0pAjAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:33:35
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.160.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:33:23.599479 2026] [security2:error] [pid 25338:tid 25338] [client 209.50.160.158:42867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houseofbates.net"] [uri "/api/.env"] [unique_id "aYpgs_u9RzFh6QrQHvKEtgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack