๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-02-24 02:25:48
(3 months ago)
209.50.164.73 - - [23/Feb/2026:19:25:48 -0700] "GET /.git/config HTTP/1.1" 301 468 "-" "Mozilla/5.0 ...
show more
209.50.164.73 - - [23/Feb/2026:19:25:48 -0700] "GET /.git/config HTTP/1.1" 301 468 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
...
show less
Web App Attack
๐ฎ๐น
VHosting
2025-12-23 20:35:41
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
Anonymous
2025-12-11 04:32:07
(5 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:13:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:13:32.795976 2025] [security2:error] [pid 901856:tid 901856] [client 209.50.164.73:46701] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bokharienterprises.com"] [uri "/.env"] [unique_id "aSVJDFJc5q81pWZdZTJgtgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:12:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:12:03.101641 2025] [security2:error] [pid 14856:tid 14856] [client 209.50.164.73:33357] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jbservicesinc.net"] [uri "/.git/HEAD"] [unique_id "aSU6o1VEWrN_lPLDN0j6xgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:59:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:59:19.437817 2025] [security2:error] [pid 31409:tid 31409] [client 209.50.164.73:31179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.iberhome.net"] [uri "/.env"] [unique_id "aSUpl7fInwQpq3AG2OuvHQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:49:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:49:14.153119 2025] [security2:error] [pid 20045:tid 20045] [client 209.50.164.73:22593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thesiteworks.com"] [uri "/.svn/wc.db"] [unique_id "aST9CoWDZ02wYsRtXjTJiAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:22:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:22:41.596475 2025] [security2:error] [pid 15589:tid 15623] [client 209.50.164.73:54335] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kd9uri.com"] [uri "/.svn/wc.db"] [unique_id "aST20SIjVFKa_KFJ49gxeAAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:05:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:05:31.632362 2025] [security2:error] [pid 24708:tid 24708] [client 209.50.164.73:44635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.meetpositivesingles.com"] [uri "/.env"] [unique_id "aSQRy6IKVokzIS6y9HjI0AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:46:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.164.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:46:25.240284 2025] [security2:error] [pid 3965261:tid 3965310] [client 209.50.164.73:33783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lcncmo.com"] [uri "/.svn/wc.db"] [unique_id "aSPjIR7XGNzpCBYjvUvnQwAAAkw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 09:11:33
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
fbarela
2025-11-07 23:00:51
(6 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
๐ง๐ท
hostseries
2025-10-15 22:39:45
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-10-14 08:49:30
(7 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force