๐บ๐ธ
ambor
2026-09-24 13:58:32
(9 hours ago)
Honeypot triggered: /wp-login.php on ifebridge.com. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS ...
show more
Honeypot triggered: /wp-login.php on ifebridge.com. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15. Method: POST
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-12 15:14:21
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
maxpower
2026-09-07 21:27:57
(2 weeks ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 209.50.180.160 (GB/United Kingdom/-): 1 in the ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 209.50.180.160 (GB/United Kingdom/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 209.50.180.160 - - [07/Sep/2026:23:27:53 +0200] "GET /wp-json/wp/v2/users HTTP/2.0" 200 4822 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" "209.50.180.160" host=circolotennispescara.it
show less
Port Scan
๐ธ๐ช
OnTheEdge
2026-09-03 21:07:50
(3 weeks ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-01 05:17:21
(3 months ago)
IM360 WAF: Suspicious access attempt to WordPress debug.log (CVE-2024-44000) MV:/wp-content/debug.lo ...
show more
IM360 WAF: Suspicious access attempt to WordPress debug.log (CVE-2024-44000) MV:/wp-content/debug.log
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-01 05:17:21
(3 months ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.production
Web App Attack
๐บ๐ธ
mnsf
2026-05-28 22:07:05
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
mind5t0rm
2025-12-31 12:59:11
(8 months ago)
(XMLRPC) WP XMLPRC Attack 209.50.180.160 (GB/United Kingdom/-): 3 in the last 3600 secs; Ports: *; D ...
show more
(XMLRPC) WP XMLPRC Attack 209.50.180.160 (GB/United Kingdom/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 209.50.180.160 - - [31/Dec/2025:19:59:07 +0700] "POST /xmlrpc.php HTTP/1.1" 403 155 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
209.50.180.160 - - [31/Dec/2025:19:59:08 +0700] "POST /xmlrpc.php HTTP/1.1" 403 155 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
209.50.180.160 - - [31/Dec/2025:19:59:08 +0700] "POST /xmlrpc.php HTTP/1.1" 403 155 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
show less
Port Scan
๐ฆ๐บ
2000cn.com.au
2025-12-02 15:58:46
(9 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:42:19
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:42:15.067123 2025] [security2:error] [pid 9943:tid 9943] [client 209.50.180.160:9997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "charamand.com"] [uri "/.svn/wc.db"] [unique_id "aS58N0hHJgixyElJ3fC7TgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 04:53:02
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:52:58.780664 2025] [security2:error] [pid 2163:tid 2163] [client 209.50.180.160:24959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title50.com"] [uri "/.git/HEAD"] [unique_id "aS5wqlMkl9mJeC-DHS1moQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 04:05:01
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:04:54.773166 2025] [security2:error] [pid 31958:tid 31958] [client 209.50.180.160:40549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathiasaspelin.com"] [uri "/.git/HEAD"] [unique_id "aS5lZiY1E1VWiDyMs--MSgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 01:14:47
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 20:14:39.355538 2025] [security2:error] [pid 1728118:tid 1728118] [client 209.50.180.160:9785] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atsllc.biz"] [uri "/.git/HEAD"] [unique_id "aS49f8FCgwc8Qei5if9zTQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:19:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:19:19.228656 2025] [security2:error] [pid 16242:tid 16242] [client 209.50.180.160:48149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.autobee.biz"] [uri "/.env"] [unique_id "aSVYd4kbfwZ9iJMGSU89qQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:34:23
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.180.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:34:15.849939 2025] [security2:error] [pid 406:tid 406] [client 209.50.180.160:37723] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kmnr.net"] [uri "/.git/HEAD"] [unique_id "aSQYh0DwK7qmT9MVmzG1uAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack