๐ฎ๐ฉ
securejdprop
2026-10-04 04:22:57
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus D ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus DROP Listed Traffic Inbound group 66).
show less
Hacking
Web App Attack
๐ฉ๐ช
NxtGenIT
2026-09-22 08:41:30
(1 week ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html?fcadbadd=1 HTTP/1.1" 200 -,
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-07-29 22:34:53
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ซ๐ท
Sklurk
2026-07-18 02:15:59
(2 months ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-09 00:07:19
(2 months ago)
Web App Attack
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-24 07:21:03
(3 months ago)
(y4) Failed scan -byebye- from 209.50.170.84 (US/United States/-): (CF_ENABLE)
Hacking
๐ซ๐ท
Sklurk
2026-06-23 03:52:28
(3 months ago)
Web App Attack
Web App Attack
๐ฌ๐ท
setupgr
2026-06-15 17:14:36
(3 months ago)
(mod_security) mod_security (id:900001) triggered by 209.50.170.84: 1 in the last 86400 secs; Ports: ...
show more
(mod_security) mod_security (id:900001) triggered by 209.50.170.84: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Mon Jun 15 20:14:36.314916 2026] [security2:error] [pid 1917071:tid 1917258] [client 209.50.170.84:56763] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "74"] [id "900001"] [msg "Blocked WP Login attempt on domain: setworldup.com"] [severity "CRITICAL"] [tag "security"] [hostname "setworldup.com"] [uri "/wp-login.php"] [unique_id "ajAy_HbrIXpbmq-1FoWDoQAAAQg"], referer: https://setworldup.com/wp-login.php
show less
Port Scan
๐บ๐ธ
octageeks.com
2026-04-20 04:06:04
(5 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐บ๐ธ
cyfordtechnologies.com
2026-03-15 05:47:17
(6 months ago)
High-abuse ASN prefix: 209.50. : Reported by Cyford API
Web App Attack
๐ช๐ธ
Gem
2026-02-13 23:19:51
(7 months ago)
Unauthorized web scan.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:29:01
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:28:57.087077 2026] [security2:error] [pid 29004:tid 29004] [client 209.50.170.84:16569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maffiniandbearce.com"] [uri "/admin/.env"] [unique_id "aYql-cSdrDrC6QesJP5DnQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:37:46
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:37:43.500169 2026] [security2:error] [pid 3822:tid 3822] [client 209.50.170.84:50873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hshs82.com"] [uri "/app/.git/config"] [unique_id "aYpvx1gFTrb8ARx1uNiMhAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:24:00
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:23:47.264147 2026] [security2:error] [pid 1538190:tid 1538190] [client 209.50.170.84:10337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotwheelguide.com"] [uri "/backup/.git/config"] [unique_id "aYpec9JDBOJkUfPQA3Yz_gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:50:46
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:50:40.366602 2026] [security2:error] [pid 14263:tid 14263] [client 209.50.170.84:54123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hoofprints.us"] [uri "/test/.git/config"] [unique_id "aYpIoPpGLnV5aZCnlkRLxQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack