๐ฉ๐ช
FeG Deutschland
2026-10-01 02:22:54
(43 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-24 19:32:45
(6 days ago)
[Fri Sep 25 05:32:44.314650 2026] [security2:error] [pid 544325] [client 209.50.169.201:26449] [clie ...
show more
[Fri Sep 25 05:32:44.314650 2026] [security2:error] [pid 544325] [client 209.50.169.201:26449] [client 209.50.169.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/"] [unique_id "arV63NRdt5LwNWOmg34BDAAAAAE"]
...
show less
Web App Attack
๐ช๐ธ
raiolanetworks.com
2026-09-21 04:40:49
(1 week ago)
Honeypot detection: Cisco ASA exploit attempt. 3 events observed. Reported automatically from a hone ...
show more
Honeypot detection: Cisco ASA exploit attempt. 3 events observed. Reported automatically from a honeypot sensor.
show less
Hacking
๐ธ๐ช
OnTheEdge
2026-09-04 05:30:02
(3 weeks ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ซ๐ท
Sklurk
2026-08-03 03:15:14
(1 month ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-08 01:34:43
(2 months ago)
Web App Attack
Web App Attack
Anonymous
2026-04-12 05:40:20
(5 months ago)
Attempt to scan vulnerabilities
Hacking
๐จ๐ฟ
lp
2026-03-07 17:53:57
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 209.50.169.201
2026-03-07T18:32:28+01 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 209.50.169.201
2026-03-07T18:32:28+01:00 vpn Access-Reject 'dvod05' station: 209.50.169.201 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ฉ๐ช
F242
2026-01-30 06:16:00
(8 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-21 12:08:18
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 07:08:14.189709 2026] [security2:error] [pid 9847:tid 9847] [client 209.50.169.201:43667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grayowl.com"] [uri "/.env"] [unique_id "aXDBrr52SqY6Wgv9RlO9YwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-20 21:44:04
(8 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-20 19:41:51
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 14:41:43.979102 2026] [security2:error] [pid 12350:tid 12350] [client 209.50.169.201:14651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bergopro.co.uk"] [uri "/.svn/wc.db"] [unique_id "aW_ad5refLt_moG1Cn3-PQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 18:01:12
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 13:01:04.575488 2026] [security2:error] [pid 30201:tid 30201] [client 209.50.169.201:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/.svn/wc.db"] [unique_id "aV6fYLTzYADMPqJhd6eHEgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-30 15:33:57
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 10:33:42.526247 2025] [security2:error] [pid 5465:tid 5465] [client 209.50.169.201:16171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.allcostaricarentals.com"] [uri "/.env"] [unique_id "aVPw1vpIy8hdKl9sqDHBbQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:33:36
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.169.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:33:30.120755 2025] [security2:error] [pid 22794:tid 22794] [client 209.50.169.201:23439] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elessenux.com"] [uri "/.svn/wc.db"] [unique_id "aVISqgSw6vHFXx7uIO5O_wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack