๐บ๐ธ
LSPCCU
2026-08-21 19:25:59
(3 days ago)
TSEC Honeypot Network report. Threat score: 61/100. Categories: Hacking. Context: 209.50.189.49 clas ...
show more
TSEC Honeypot Network report. Threat score: 61/100. Categories: Hacking. Context: 209.50.189.49 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
Hacking
๐ซ๐ท
Sklurk
2026-08-01 00:26:09
(3 weeks ago)
Web App Attack
Web App Attack
๐ฌ๐ง
pinguin
2026-07-03 20:27:57
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /wp-json/gravitysmtp/v1/tests/mock-data
UA: curl/8.7.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-01-16 22:59:41
(7 months ago)
Auto-ban: >3000 req/min op 2026-01-16
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-16 07:12:43
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 02:12:35.811341 2026] [security2:error] [pid 18986:tid 18986] [client 209.50.189.49:42985] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sasquatchproductionsltd.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sasquatchproductionsltd.com"] [uri "/s3cmd.ini"] [unique_id "aWnk48WZuOChjcW-rKgsJwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-01-16 07:10:31
(7 months ago)
Try to access /.aws/credentials
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 05:04:28
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 00:04:24.115483 2026] [security2:error] [pid 2961803:tid 2961813] [client 209.50.189.49:50627] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||saryatech.pershia.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "saryatech.pershia.net"] [uri "/s3cmd.ini"] [unique_id "aWnG2IfTInQiLBE7Z7WmYQAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-30 11:10:46
(7 months ago)
wordpress-trap
Web App Attack
Anonymous
2025-12-10 09:37:25
(8 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:33:38
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:33:35.418017 2025] [security2:error] [pid 16741:tid 16759] [client 209.50.189.49:32541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.groceriesfromscratch.andyboynton.com"] [uri "/.svn/wc.db"] [unique_id "aSaRLx0iM_MjIA1Wx89yhwAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 02:53:11
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:53:03.981224 2025] [security2:error] [pid 19260:tid 19260] [client 209.50.189.49:16375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.asociacioncopan.org"] [uri "/.git/HEAD"] [unique_id "aSZrj7xem-rj0nmSJTF2HAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-24 11:52:40
(9 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:24:45
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:24:40.664123 2025] [security2:error] [pid 4097:tid 4097] [client 209.50.189.49:50693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.randymeisner.com"] [uri "/.svn/wc.db"] [unique_id "aSQkWOAS73be2CW4eNWMhgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:00:15
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:00:05.279434 2025] [security2:error] [pid 30762:tid 30762] [client 209.50.189.49:45929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bicaco.com"] [uri "/.git/HEAD"] [unique_id "aSQelUbhpOtWRidmVlprfwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:41:50
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.189.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:41:46.711422 2025] [security2:error] [pid 17266:tid 17266] [client 209.50.189.49:17219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "belgium-boat-registration.com"] [uri "/.git/HEAD"] [unique_id "aSQaSmYaQWaWzs4O2lgL4AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack