🇮🇩
securejdprop
2026-09-04 19:13:06
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus D ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus DROP Listed Traffic Inbound group 66).
show less
Hacking
Web App Attack
🇩🇪
NxtGenIT
2026-09-03 11:22:24
(2 days ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html?fcadbadd=1 HTTP/1.1" 200 -,
Brute-Force
🇸🇪
OnTheEdge
2026-09-02 17:28:15
(2 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇵🇱
Budyn
2026-08-21 10:08:15
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.space | URI: /wp-admin/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇫🇷
Sklurk
2026-08-14 09:25:29
(3 weeks ago)
Web App Attack
Web App Attack
🇩🇪
LRob
2026-06-14 19:15:23
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇫🇮
inlink.ltd
2026-05-25 12:03:29
(3 months ago)
Known malicious PHP file or CMS probe
Web App Attack
Anonymous
2026-02-15 04:31:11
(6 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇺🇸
TPI-Abuse
2025-12-09 05:20:34
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 00:20:27.536280 2025] [security2:error] [pid 10264:tid 10264] [client 209.50.189.31:36687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "austintrauma.com"] [uri "/.svn/wc.db"] [unique_id "aTexm8WMlEjRaEYU60Q-XwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-08 06:20:50
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 01:20:38.221718 2025] [security2:error] [pid 12496:tid 12496] [client 209.50.189.31:30097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schonfashion.com"] [uri "/.env"] [unique_id "aTZuNgCbhzJOVWiH9hU6zAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-05 16:46:23
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 11:46:17.224693 2025] [security2:error] [pid 6943:tid 6943] [client 209.50.189.31:44899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thinkingepic.com"] [uri "/.git/HEAD"] [unique_id "aTMMWUgrPopHi9tQ2AnywwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
madeit
2025-11-30 04:34:05
(9 months ago)
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 21:02:56
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 16:02:51.251298 2025] [security2:error] [pid 246669:tid 246740] [client 209.50.189.31:38899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aafmhk2015.aafm.us"] [uri "/.git/HEAD"] [unique_id "aSdq-yLrtyOfWjzEzADqxgAAAgo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 17:28:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 12:27:58.785523 2025] [security2:error] [pid 26771:tid 26902] [client 209.50.189.31:11669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hdtv55.com"] [uri "/.git/HEAD"] [unique_id "aSc4nlRqYPjEDktSOg77PQAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 09:14:34
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 04:14:27.731489 2025] [security2:error] [pid 9607:tid 9693] [client 209.50.189.31:37215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fnaandpartners.oplconnect.com"] [uri "/.env"] [unique_id "aSbE8_kDcg6wFbLmNJ01UgAAAhU"]
show less
Brute-Force
Bad Web Bot
Web App Attack