๐บ๐ธ
drewf.ink
2026-09-02 02:22:33
(3 hours ago)
[02:22] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[02:22] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
๐ซ๐ท
Sklurk
2026-08-14 09:18:24
(2 weeks ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-29 01:29:56
(1 month ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-15 20:41:30
(1 month ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-06-20 05:18:50
(2 months ago)
Web App Attack
Web App Attack
Anonymous
2025-12-31 07:17:21
(8 months ago)
"GET /.aws/credentials HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 06:24:18
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:24:12.302293 2025] [security2:error] [pid 10098:tid 10098] [client 209.50.179.79:50343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentsavagelaw.com"] [uri "/.env"] [unique_id "aVIejPg6HgyvctOcsvbjWAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:22:11
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:22:04.446433 2025] [security2:error] [pid 2191:tid 2191] [client 209.50.179.79:22873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "freightmotivity.com"] [uri "/.svn/wc.db"] [unique_id "aVIB7D8DvVLHsiBkAXdofwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:04:41
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:04:34.837633 2025] [security2:error] [pid 17718:tid 17718] [client 209.50.179.79:43943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexsource.com"] [uri "/.git/HEAD"] [unique_id "aVH90m69fvhYpjqfOL5igAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 11:29:00
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:28:52.357915 2025] [security2:error] [pid 18314:tid 18314] [client 209.50.179.79:41503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.joepeters.org"] [uri "/.env"] [unique_id "aSbkdKZR3jQjqa8kJtPb9wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 09:17:05
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 04:16:58.113716 2025] [security2:error] [pid 9389:tid 9389] [client 209.50.179.79:17737] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.readyremotely.com"] [uri "/.env"] [unique_id "aSbFirIsWnlMP0LbXA-zSAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:51:27
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:51:19.309472 2025] [security2:error] [pid 2227584:tid 2227584] [client 209.50.179.79:54169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.elevese.com"] [uri "/.svn/wc.db"] [unique_id "aSZdFxExGNJ8PRnWmGuTZwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:24:36
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:24:30.824939 2025] [security2:error] [pid 8167:tid 8167] [client 209.50.179.79:34537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kennedysplace.com"] [uri "/.git/HEAD"] [unique_id "aSVZrmoIri3rX7fozOzWfAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:41:13
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:41:05.829984 2025] [security2:error] [pid 3932:tid 3932] [client 209.50.179.79:17027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aquascapes.net"] [uri "/.svn/wc.db"] [unique_id "aSVPgSlbBI3ITJ5FczyD5wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:24:37
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.179.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:24:32.024147 2025] [security2:error] [pid 11947:tid 11947] [client 209.50.179.79:21679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.paguilar.com"] [uri "/.env"] [unique_id "aSVLoO3uJmpjLUnAq-TAvAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack