๐ฌ๐ท
setupgr
2026-06-14 12:37:12
(10 hours ago)
(mod_security) mod_security (id:900001) triggered by 209.50.162.71: 1 in the last 86400 secs; Ports: ...
show more
(mod_security) mod_security (id:900001) triggered by 209.50.162.71: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Sun Jun 14 15:37:11.761744 2026] [security2:error] [pid 921870:tid 922008] [client 209.50.162.71:53765] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "74"] [id "900001"] [msg "Blocked WP Login attempt on domain: mail.babis.photo"] [severity "CRITICAL"] [tag "security"] [hostname "mail.babis.photo"] [uri "/wp-login.php"] [unique_id "ai6gdyiyK_EXlfCi56cUiQAAAE8"], referer: https://mail.babis.photo/wp-login.php
show less
Port Scan
๐ฉ๐ช
iNetWorker
2026-06-13 07:09:39
(1 day ago)
trolling for resource vulnerabilities
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-06-12 04:23:58
(2 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฎ๐ฉ
zam
2026-06-11 20:06:41
(3 days ago)
209.50.162.71 - - [11/Jun/2026:20:06:23 +0000] "POST /wp-login.php HTTP/1.1" 301 277
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-10 15:56:32
(4 days ago)
(y4) Failed scan -byebye- from 209.50.162.71 (US/United States/-): (CF_ENABLE)
Hacking
๐ฉ๐ช
LRob.fr
2026-06-10 04:45:22
(4 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-02 20:23:11
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 15:23:07.267530 2026] [security2:error] [pid 31812:tid 31812] [client 209.50.162.71:21971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.805.productions.inetbrain.com"] [uri "/.svn/wc.db"] [unique_id "aVgpK9GHjc5crLiX8VoJrAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 00:53:00
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 19:52:47.993962 2025] [security2:error] [pid 4731:tid 4731] [client 209.50.162.71:15909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "business.lsd36.com"] [uri "/.git/HEAD"] [unique_id "aVRz3w8IoPT_s2517dtXEwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-30 20:37:06
(5 months ago)
"GET /.aws/credentials HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
jcbriar
2025-12-30 07:17:08
(5 months ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:45
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ซ๐ฎ
Shaik Sai Meera
2025-12-29 08:40:16
(5 months ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-29 05:10:25
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:10:19.293100 2025] [security2:error] [pid 25687:tid 25687] [client 209.50.162.71:55125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackcanyonguides.com"] [uri "/.svn/wc.db"] [unique_id "aVINOwsPFpTa1z2bTigQBAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:44:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:44:47.278509 2025] [security2:error] [pid 6476:tid 6476] [client 209.50.162.71:27883] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkhorseyachting.com"] [uri "/.svn/wc.db"] [unique_id "aVIHP6FlTC8QEOE9C6EPOQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-12-28 03:04:11
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot