๐บ๐ธ
lostswordfish.com
2026-06-13 08:14:06
(5 hours ago)
Wordfence waf block on parsol
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-12 10:33:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฒ๐น
Malta
2026-06-10 14:22:18
(2 days ago)
209.50.161.111 - - [10/Jun/2026:16:22:18 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Lin ...
show more
209.50.161.111 - - [10/Jun/2026:16:22:18 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐บ๐ธ
LSPCCU
2026-05-08 08:51:18
(1 month ago)
TSEC Honeypot Network report. Threat score: 68/100. Categories: Hacking. Honeypot: ssh-telnet, cowri ...
show more
TSEC Honeypot Network report. Threat score: 68/100. Categories: Hacking. Honeypot: ssh-telnet, cowrie. Context: 209.
show less
Hacking
Anonymous
2026-03-18 04:57:50
(2 months ago)
Forum/form spam
Web Spam
๐ฑ๐ป
garmtech.com
2026-01-23 22:38:48
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-38.209.50.161.111.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-38.209.50.161.111.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-21 15:26:27
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 10:26:19.555051 2026] [security2:error] [pid 14775:tid 14775] [client 209.50.161.111:21303] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radtraininginc.com"] [uri "/.git/HEAD"] [unique_id "aXDwG9mUiuXwg40ZLAPpYAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-01-21 11:14:42
(4 months ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-21 03:46:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 22:46:19.453087 2026] [security2:error] [pid 21567:tid 21567] [client 209.50.161.111:59041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.git/HEAD"] [unique_id "aXBMCxzEJ-6Y9OMQQWe4igAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-20 21:44:18
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
Anonymous
2026-01-19 20:35:39
(4 months ago)
Forum/form spam
Web Spam
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:22
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-12-30 08:34:56
(5 months ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:58:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:58:10.870891 2025] [security2:error] [pid 19021:tid 19021] [client 209.50.161.111:56685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cheappartyballoons.com"] [uri "/.env"] [unique_id "aVIKYjVIyJWkiTakGgT4PAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 03:28:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 22:27:55.188030 2025] [security2:error] [pid 24429:tid 24429] [client 209.50.161.111:57751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "casalaaldehuela.com"] [uri "/.env"] [unique_id "aVH1O-0-Gx2xdhAfKJTNRAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack