Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=19; exact paths: /xmlrpc.php
Web App Attack
🇺🇸
nyt
2026-07-07 04:42:03
(1 month ago)
WP User Enumeration, WP login POST blocked by WAF
Brute-Force
Web App Attack
🇬🇧
PeravixGroup
2026-05-06 13:36:45
(3 months ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
🇺🇸
myagent.site
2026-02-20 05:09:55
(6 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
🇩🇪
BlueWire Hosting
2026-02-13 06:09:30
(6 months ago)
Probing websites for vulnerabilities
SQL Injection
Web App Attack
🇩🇪
Packets-Decreaser.NET
2025-12-31 00:58:58
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇺🇸
TPI-Abuse
2025-12-29 06:06:29
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:06:24.293216 2025] [security2:error] [pid 9232:tid 9232] [client 209.50.185.20:31113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tatying.com"] [uri "/.svn/wc.db"] [unique_id "aVIaYJCa0Vi1f406X0c1zAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 04:33:48
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:33:41.604792 2025] [security2:error] [pid 19357:tid 19357] [client 209.50.185.20:54795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aam-artists.com"] [uri "/.svn/wc.db"] [unique_id "aVIEpboOTL4cDCtFqw7sAwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
GabrielJST
2025-12-27 13:30:08
(8 months ago)
*Port Scan* detected from 209.50.185.20 (TH/Thailand/-).
Port Scan
🇦🇺
MAGIC
2025-12-24 05:06:24
(8 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇧🇷
hostseries
2025-12-24 04:49:54
(8 months ago)
Trigger: LF_DISTATTACK
Brute-Force
🇺🇸
TPI-Abuse
2025-11-24 09:13:36
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:13:27.861291 2025] [security2:error] [pid 26731:tid 26731] [client 209.50.185.20:9357] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.waggonerfinancial.com"] [uri "/.svn/wc.db"] [unique_id "aSQht9dl33FNH6xrSLbUCgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:20:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:20:26.438602 2025] [security2:error] [pid 27184:tid 27184] [client 209.50.185.20:13515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.daisyinvitations.com"] [uri "/.env"] [unique_id "aSQHOo9E3CyyB_r2GhTuUAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:02:57
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:02:51.552089 2025] [security2:error] [pid 12006:tid 12082] [client 209.50.185.20:46195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.managementlaw.com"] [uri "/.env"] [unique_id "aSQDG0DKyspBjqfQ2lVB9AAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:19:20
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:18:58.425697 2025] [security2:error] [pid 20122:tid 20122] [client 209.50.185.20:30059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bzbdesigns.com"] [uri "/.svn/wc.db"] [unique_id "aSP40ixjVX7dflIXr7QflAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack