๐บ๐ธ
Ben Schoolland
2026-10-05 18:13:24
(2 days ago)
Requested known WordPress backdoor/scanner-only paths. No legitimate use.
Bad Web Bot
Web App Attack
๐บ๐ธ
Ben Schoolland
2026-09-21 14:00:31
(2 weeks ago)
Requested known WordPress backdoor/scanner-only paths. No legitimate use.
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-09 13:05:56
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-28 23:06:19
(4 months ago)
Scanning/Probing (34)
Brute-Force
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-05-03 08:18:46
(5 months ago)
Honeypot detection: Memcached unauthorized access / amplification attempt on port 2375. Severity: HI ...
show more
Honeypot detection: Memcached unauthorized access / amplification attempt on port 2375. Severity: HIGH. Aaran.cloud
show less
Hacking
Exploited Host
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(6 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ง๐ช
voormedia
2026-03-05 16:09:10
(7 months ago)
Accessed trap at '/.env'
Web App Attack
๐ฉ๐ช
conseilgouz
2026-01-17 09:29:42
(8 months ago)
coe-17 : Block hidden directories=>/.env(/)
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-17 00:18:48
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 19:18:40.864272 2026] [security2:error] [pid 2167198:tid 2167198] [client 209.50.164.35:18723] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.peazy.net"] [uri "/.env"] [unique_id "aWrVYALEwgvIXwRoz6ZUjAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
fbarela
2025-12-20 04:00:33
(9 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-11-30 12:11:08
(10 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 13:57:26
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 08:57:18.540883 2025] [security2:error] [pid 9091:tid 9091] [client 209.50.164.35:13305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mitchellamazing.com"] [uri "/wp-config.php"] [unique_id "aSmqPqF4LYgDAvXJA9a4KQAAAAE"], referer: http://amazingstairs.com/wp-config.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:01:33
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:01:28.316438 2025] [security2:error] [pid 22124:tid 22124] [client 209.50.164.35:58971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.missyallen.com"] [uri "/.svn/wc.db"] [unique_id "aSVGOCqHQkElW6f1IhFKQgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:26:16
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:26:09.384315 2025] [security2:error] [pid 20415:tid 20415] [client 209.50.164.35:10163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rantell.net"] [uri "/.env"] [unique_id "aSU98cug-_oIRKLxx6IMNgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:44:31
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:44:25.060093 2025] [security2:error] [pid 28684:tid 28684] [client 209.50.164.35:16485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.valueandmeaning.com"] [uri "/.git/HEAD"] [unique_id "aSU0KcEg5Rru10LcyltY8gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack