๐ฉ๐ช
raspi4
2026-04-09 21:26:25
(1 month ago)
Fail2Ban Ban Triggered
Brute-Force
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ฆ๐บ
oncord
2026-02-14 05:01:05
(3 months ago)
Form spam
Web Spam
Anonymous
2026-01-30 03:50:22
(4 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
Dolutech.com
2026-01-02 17:19:27
(5 months ago)
Bruteforce Attack Detected
Brute-Force
Anonymous
2025-12-22 14:20:31
(5 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-11-26 07:34:21
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:46:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:46:41.519425 2025] [security2:error] [pid 16843:tid 16843] [client 209.50.161.13:49529] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gemconsulting.world"] [uri "/.git/HEAD"] [unique_id "aSQbca0yVUjyVsYOF3qt8gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:59:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:59:21.384041 2025] [security2:error] [pid 9473:tid 9473] [client 209.50.161.13:32511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.1cdn.com"] [uri "/.svn/wc.db"] [unique_id "aSQQWc6leHRd-spOhSmj3wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:56:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:56:33.755820 2025] [security2:error] [pid 30478:tid 30478] [client 209.50.161.13:30047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dorismitchell.com.billymitchell.com"] [uri "/.git/HEAD"] [unique_id "aSQBoY1byqct2YFtyDZB0QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:29:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:29:47.076197 2025] [security2:error] [pid 18942:tid 18942] [client 209.50.161.13:59489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wookheo.com"] [uri "/.env"] [unique_id "aSP7W5JItljH-GwV-EfViAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:21:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:21:46.608412 2025] [security2:error] [pid 16253:tid 16253] [client 209.50.161.13:53565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.warshaw1.com"] [uri "/.svn/wc.db"] [unique_id "aSPdWm95idbbAfI7_HUJcAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-16 12:46:14
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-15 14:49:29
(7 months ago)
GlobalProtect login attempts with user jtiberia.
VPN IP
Brute-Force
Anonymous
2025-10-14 10:47:51
(7 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force