🇨🇿
Countryman
2026-09-04 00:10:01
(22 hours ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
Anonymous
2026-09-03 21:10:29
(1 day ago)
2026-09-03T23:10:29.274286+02:00 polaris wp(bikeschool.co.za)[848423]: Authentication attempt for un ...
show more
2026-09-03T23:10:29.274286+02:00 polaris wp(bikeschool.co.za)[848423]: Authentication attempt for unknown user jmgarciacid from 209.50.178.118
...
show less
Brute-Force
Web App Attack
🇸🇪
OnTheEdge
2026-09-03 07:04:35
(1 day ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇸🇪
OnTheEdge
2026-09-03 07:04:35
(1 day ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇺🇸
ambor
2026-09-02 02:27:14
(2 days ago)
Honeypot access: WordPress XML-RPC attack attempt. Path: /xmlrpc.php
Brute-Force
Web App Attack
🇫🇷
Sklurk
2026-06-23 05:46:32
(2 months ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-06-20 00:47:11
(2 months ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-02-19 03:00:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:00:46.214830 2026] [security2:error] [pid 27386:tid 27386] [client 209.50.178.118:54511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kenmalone.com"] [uri "/admin/.env"] [unique_id "aZZ83lcWImzUGd09UIOp2QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 22:52:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 17:52:51.209898 2026] [security2:error] [pid 7103:tid 7103] [client 209.50.178.118:58429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanmetermailing.com"] [uri "/app/.env"] [unique_id "aZZCw10PFMooA8nWAfxAiQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 20:16:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 15:16:36.458538 2026] [security2:error] [pid 9115:tid 9115] [client 209.50.178.118:47049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trasimeno.ws"] [uri "/api/.env"] [unique_id "aZYeJO-efYjd82kk-q9seAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 14:15:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 09:15:21.064725 2026] [security2:error] [pid 921522:tid 921529] [client 209.50.178.118:64763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wwwhst.com"] [uri "/new/.git/config"] [unique_id "aZXJeSaU7x6XAzfgnPhodwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 11:57:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.178.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:57:49.835968 2026] [security2:error] [pid 3733:tid 3733] [client 209.50.178.118:50193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wasabioldies.com"] [uri "/frontend/.env"] [unique_id "aZWpPRHoNsZ5EB-_lmPGfQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-04 16:17:00
(10 months ago)
Unauthorized connection attempt
Brute-Force
🇧🇪
cmbplf
2025-10-07 04:26:15
(10 months ago)
2.740 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot