๐ฌ๐ท
setupgr
2026-06-13 05:34:26
(8 hours ago)
(mod_security) mod_security (id:900001) triggered by 209.50.183.115: 1 in the last 86400 secs; Ports ...
show more
(mod_security) mod_security (id:900001) triggered by 209.50.183.115: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Sat Jun 13 08:34:22.646074 2026] [security2:error] [pid 568462:tid 568605] [client 209.50.183.115:10621] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "74"] [id "900001"] [msg "Blocked WP Login attempt on domain: ions.gr"] [severity "CRITICAL"] [tag "security"] [hostname "ions.gr"] [uri "/wp-login.php"] [unique_id "aizr3n3MZME_v5maSVSgzQAAAVA"], referer: https://ions.gr/wp-login.php
show less
Port Scan
๐ซ๐ท
ELYAZ
2026-06-11 13:41:16
(2 days ago)
(y4) Failed scan -byebye- from 209.50.183.115 (DE/Germany/-): (CF_ENABLE)
Hacking
๐ฑ๐ป
garmtech.com
2026-06-10 06:45:31
(3 days ago)
IM360 WAF: Prohibited WordPress username login/registration
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-10 01:45:35
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-09 18:08:46
(3 days ago)
(y4) Failed scan -byebye- from 209.50.183.115 (DE/Germany/-): (CF_ENABLE)
Hacking
๐ง๐ช
voormedia
2026-03-05 16:09:25
(3 months ago)
Accessed trap at '/.git/config'
Web App Attack
Anonymous
2026-01-05 20:20:31
(5 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
๐ซ๐ท
ingroscart.it
2025-11-26 03:36:35
(6 months ago)
(mod_security) mod_security triggered on hostname [redacted] 209.50.183.115 (DE/Germany/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-11-26 01:41:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:41:24.400164 2025] [security2:error] [pid 27487:tid 27487] [client 209.50.183.115:33489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rotentendales.com"] [uri "/.env"] [unique_id "aSZaxDsgp811dZaORapZygAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:21:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:21:34.917874 2025] [security2:error] [pid 1116:tid 1116] [client 209.50.183.115:25447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tibbertonshropshire.org"] [uri "/.env"] [unique_id "aSZWHt93iCrPW93Z6VTDhQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:32:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:30:07.522839 2025] [security2:error] [pid 15938:tid 15964] [client 209.50.183.115:54053] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.layoverlocations.com"] [uri "/.svn/wc.db"] [unique_id "aSQln4aBygiwvlm31viXkgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:47:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:46:57.372406 2025] [security2:error] [pid 28605:tid 28605] [client 209.50.183.115:59597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ampstudio.eu"] [uri "/.git/HEAD"] [unique_id "aSQNcZid7_zwhahiwAinuQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:57:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:56:55.121275 2025] [security2:error] [pid 15996:tid 15996] [client 209.50.183.115:37765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.noisepie.com"] [uri "/.env"] [unique_id "aSPzp0D6ZPo3do5JLkW9kwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 13:35:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.183.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 08:35:27.048503 2025] [security2:error] [pid 2756:tid 2756] [client 209.50.183.115:57507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.battlestem.com"] [uri "/.env"] [unique_id "aSMNn7Igci9VxfRxhByCdwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-21 18:49:43
(6 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/21 12:36:03
Port Scan
Brute-Force
Exploited Host
Web App Attack