π«π·
Sklurk
2026-07-07 17:21:16
(2 weeks ago)
Web App Attack
Web App Attack
Anonymous
2026-04-22 13:51:03
(3 months ago)
Malicious activity detected
Hacking
Web App Attack
π¦πΊ
RedBear IT
2026-03-26 10:00:37
(4 months ago)
"DDoS against public endpoint"
DDoS Attack
πΊπΈ
TPI-Abuse
2026-02-20 09:37:31
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 04:37:26.090316 2026] [security2:error] [pid 9608:tid 9608] [client 209.50.168.183:10377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cobbwebb.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cobbwebb.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZgrVu6Fe4ZnQ3KSUe91vgAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
ketovoila.pl
2026-01-10 10:41:07
(6 months ago)
ketovoila.pl HONEYPOT traffic: count=1, paths=1; sample_path=ketovoila.pl/.aws/credentials; UA=Mozil ...
show more
ketovoila.pl HONEYPOT traffic: count=1, paths=1; sample_path=ketovoila.pl/.aws/credentials; UA=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36; window=2026-01-10T10:19:57Z..2026-01-10T10:19:57Z
show less
Port Scan
Hacking
Brute-Force
Anonymous
2025-12-11 14:06:46
(7 months ago)
botnet
DDoS Attack
Anonymous
2025-11-26 07:44:04
(8 months ago)
botnet
DDoS Attack
πΊπΈ
TPI-Abuse
2025-11-25 07:04:52
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:04:49.670706 2025] [security2:error] [pid 6741:tid 6741] [client 209.50.168.183:51925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mathieu.bouville.name"] [uri "/.git/HEAD"] [unique_id "aSVVEeHsFF2bHqHN3BlmWgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 06:51:08
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:51:00.915157 2025] [security2:error] [pid 27598:tid 27598] [client 209.50.168.183:10411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cardinalcouncilgc.org"] [uri "/.env"] [unique_id "aSQAVMw9hmPPVG0Pmsp4RAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:41:01
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:40:53.445886 2025] [security2:error] [pid 1825:tid 1825] [client 209.50.168.183:59155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.snowfection.com"] [uri "/.env"] [unique_id "aSPh1aAKk6Ot6UChp1jV5wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 03:58:37
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:58:34.479500 2025] [security2:error] [pid 10399:tid 10399] [client 209.50.168.183:18203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3rdplanetguide.net"] [uri "/.git/HEAD"] [unique_id "aSPX6qqopTHVeahDbvgNrQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-25 03:08:17
(9 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
π¨π¦
wil.com
2025-10-16 04:40:56
(9 months ago)
GlobalProtect login attempts with user atsec.
VPN IP
Brute-Force
π§π·
hostseries
2025-10-13 11:47:10
(9 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-10-06 22:59:50
(9 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.06 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.06 is noted in report timestamp
show less
Hacking
Brute-Force