Anonymous
2026-07-29 07:00:00
(9 hours ago)
Apache probe; attempts=29; exact paths: /xmlrpc.php
Web App Attack
๐ช๐ธ
librebit
2026-06-16 08:27:30
(1 month ago)
Brute force
Brute-Force
๐ฉ๐ช
LRob
2026-06-12 02:30:32
(1 month ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
ctrlpew
2026-05-19 01:00:57
(2 months ago)
WordPress login brute-force botnet targeting ctrlpew.com. Distributed IPs cycling every 3 seconds wi ...
show more
WordPress login brute-force botnet targeting ctrlpew.com. Distributed IPs cycling every 3 seconds with UA rotation. All attempts against non-existent usernames. 2026-05-18.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:11:17
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:11:06.844982 2026] [security2:error] [pid 22471:tid 22471] [client 209.50.171.241:35313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinkycouple4u.com"] [uri "/.env.local"] [unique_id "aYqhygvUitPhUnctTFsRgQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 01:54:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 20:54:42.585798 2026] [security2:error] [pid 6232:tid 6232] [client 209.50.171.241:55927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madandproud.com"] [uri "/v2/.git/config"] [unique_id "aYqP4lYSTke-qesvACp-QAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:33:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:33:43.584972 2026] [security2:error] [pid 12843:tid 12870] [client 209.50.171.241:21087] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kellenlee.com"] [uri "/backend/.env"] [unique_id "aYpu1_A-0hoRFyiKDvyfHAAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-23 14:31:59
(6 months ago)
2026-01-23T16:31:59.152944+02:00 zanati wp(www.sahpa.co.za)[191845]: Blocked authentication attempt ...
show more
2026-01-23T16:31:59.152944+02:00 zanati wp(www.sahpa.co.za)[191845]: Blocked authentication attempt for [email protected] from 209.50.171.241
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 18:11:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 13:11:22.222484 2026] [security2:error] [pid 14833:tid 14833] [client 209.50.171.241:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kryptonome.com"] [uri "/.env"] [unique_id "aV6hylnkU4oawX2X4NKlKQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:46
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฎ๐น
VHosting
2025-12-23 11:08:25
(7 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
Anonymous
2025-12-01 08:49:11
(7 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:49:46
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:49:39.578928 2025] [security2:error] [pid 15985:tid 15985] [client 209.50.171.241:28729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tijuana-bibles.tijuanabible.org"] [uri "/.env"] [unique_id "aSQAA8i1U_axOiu5jJIn-AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:38:14
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:38:07.868607 2025] [security2:error] [pid 2893:tid 2912] [client 209.50.171.241:52331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nelsonyung.com"] [uri "/.git/HEAD"] [unique_id "aSPhLyZWVzJkk5khHgNi7QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 03:51:07
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.171.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:50:45.680015 2025] [security2:error] [pid 3255765:tid 3255765] [client 209.50.171.241:28001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.blanchebb.com"] [uri "/.svn/wc.db"] [unique_id "aSPWFTep2RVKF8MpJhpRfAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack