🇺🇸
Ben Schoolland
2026-09-13 11:37:53
(1 day ago)
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legiti ...
show more
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legitimate use.
show less
Bad Web Bot
Web App Attack
🇸🇪
OnTheEdge
2026-09-04 10:54:59
(1 week ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇸🇪
OnTheEdge
2026-09-02 19:07:14
(1 week ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇪🇸
librebit
2026-05-17 04:59:42
(3 months ago)
Brute force
Brute-Force
🇪🇸
librebit
2026-05-15 03:26:50
(3 months ago)
RDWeb scan
Web App Attack
🇺🇸
TPI-Abuse
2026-01-16 22:39:51
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 17:39:45.326039 2026] [security2:error] [pid 25892:tid 25892] [client 209.50.169.189:38651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.goodideagirl.com"] [uri "/.env"] [unique_id "aWq-MS_8xHF_1Y9EX9AwRQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-16 20:54:54
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 15:54:47.752842 2026] [security2:error] [pid 13404:tid 13404] [client 209.50.169.189:58129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mac136.org"] [uri "/.env"] [unique_id "aWqll8R89adzfS5EzDzB5AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-16 19:50:04
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 14:49:56.116266 2026] [security2:error] [pid 31213:tid 31240] [client 209.50.169.189:28999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.property-management-companies-chicago.com"] [uri "/.env"] [unique_id "aWqWZEo_Dj7XmIZakttqrAAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
Shaik Sai Meera
2025-12-30 17:45:14
(8 months ago)
IM360 WAF: Hidden file access
Brute-Force
🇩🇪
paissangroup
2025-12-30 17:37:35
(8 months ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 06:03:34
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:03:26.303169 2025] [security2:error] [pid 1266:tid 1266] [client 209.50.169.189:20249] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cayman-islands-real-estate.com"] [uri "/.env"] [unique_id "aVIZrgT4irm9woEudk0uJwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-28 16:18:43
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 11:18:20.872538 2025] [security2:error] [pid 1711398:tid 1711401] [client 209.50.169.189:46297] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rawsynergy.com"] [uri "/.git/HEAD"] [unique_id "aVFYTPs7bEQg9jsRg9lh4wAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-29 09:30:37
(10 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2025-10-20 17:13:15
(10 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇨🇦
wil.com
2025-10-17 11:48:20
(10 months ago)
GlobalProtect login attempts with user icexemptions.
VPN IP
Brute-Force