๐ซ๐ท
Sklurk
2026-07-30 01:25:37
(12 hours ago)
Web App Attack
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-22 23:06:38
(1 month ago)
[Tue Jun 23 09:06:37.827042 2026] [security2:error] [pid 175435] [client 209.50.166.142:47941] [clie ...
show more
[Tue Jun 23 09:06:37.827042 2026] [security2:error] [pid 175435] [client 209.50.166.142:47941] [client 209.50.166.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/xmlrpc.php"] [unique_id "ajm__aeEnw7m9rVJZfEvoAAAAAs"]
...
show less
Web App Attack
๐จ๐ญ
4server
2026-05-19 03:27:09
(2 months ago)
[TueMay1905:27:05.5188742026][security2:error][pid2889443:tid2889464][client209.50.166.142:0]ModSecu ...
show more
[TueMay1905:27:05.5188742026][security2:error][pid2889443:tid2889464][client209.50.166.142:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"giuristifriburgo.ch\"][uri\"/xmlrpc.php\"][unique_id\"agvYibxpmF4vqMMkQk63CwAAABI\"]
show less
Hacking
Web App Attack
๐บ๐ธ
windowsforum
2026-02-14 02:18:59
(5 months ago)
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, url, password_confirm, ...
show more
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, url, password_confirm, username=RachelBlac
show less
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-10 03:37:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:37:41.036114 2026] [security2:error] [pid 26170:tid 26170] [client 209.50.166.142:28237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ibcountn.com"] [uri "/.env"] [unique_id "aYqoBaUbTvPO_8ren4dzCgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:58:48
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:58:35.942123 2026] [security2:error] [pid 27739:tid 27739] [client 209.50.166.142:19409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingmansvc.com"] [uri "/v2/.git/config"] [unique_id "aYqe29y1xY-wBY2ADSk7KwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:32:18
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:32:11.713486 2026] [security2:error] [pid 11732:tid 11732] [client 209.50.166.142:37599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevamra.com"] [uri "/api/.env"] [unique_id "aYp8i_tDh4ejPvxpCWJ3pAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:56:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:56:22.500128 2026] [security2:error] [pid 26285:tid 26285] [client 209.50.166.142:48883] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kennedimoore.click"] [uri "/new/.git/config"] [unique_id "aYp0JvsJscWMA0hDYuQZwwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:06:53
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:06:49.313898 2026] [security2:error] [pid 23648:tid 23648] [client 209.50.166.142:12353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keaborner.com"] [uri "/.env.local"] [unique_id "aYpoiVSazwekWF2W91SpSAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:59:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.166.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:59:50.112427 2026] [security2:error] [pid 27066:tid 27066] [client 209.50.166.142:50893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katemcleod.net"] [uri "/new/.git/config"] [unique_id "aYpY1hccP35l3Vw3VKRvYQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-01-24 00:32:09
(6 months ago)
Wordpress_xmlrpc_attack
Bad Web Bot
Anonymous
2026-01-16 12:19:57
(6 months ago)
Forum/form spam
Web Spam
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:50
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-11-14 09:09:42
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
techboy117
2025-11-14 00:46:07
(8 months ago)
Blocking due to password spraying.
Brute-Force