🇭🇷
bubausluge
2026-09-13 14:24:06
(16 hours ago)
Blocked by https://aegis.hr — WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-09-13 ...
show more
Blocked by https://aegis.hr — WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-09-13 13:49:09 to 2026-09-13 13:49:09
show less
Web App Attack
Hacking
🇨🇦
KIsmay
2026-09-13 12:21:02
(19 hours ago)
2026-09-13T07:28:54.238224-04:00 www4 WPAudit[3960108]: 209.50.190.194 www.nelsonbcwelding.com "Goos ...
show more
2026-09-13T07:28:54.238224-04:00 www4 WPAudit[3960108]: 209.50.190.194 www.nelsonbcwelding.com "Goosee-Audit/1.0 (+internal-security-audit)" sbd-admin:Admin2024 FAIL
2026-09-13T07:29:02.040208-04:00 www4 WPAudit[3954769]: 209.50.190.194 valhallasafety.com "Goosee-Audit/1.0 (+internal-security-audit)" sbd-admin:Admin2025 FAIL
2026-09-13T07:36:00.463542-04:00 www4 WPAudit[3960108]: 209.50.190.194 www.nelsonbcwelding.com "Goosee-Audit/1.0 (+internal-security-audit)" sbd-admin:testing FAIL
2026-09-13T07:36:41.914820-04:00 www4 WPAudit[3961043]: 209.50.190.194 valhallasafety.com "Goosee-Audit/1.0 (+internal-security-audit)" sbd-admin:babygirl FAIL
2026-09-13T08:21:01.137429-04:00 www4 WPAudit[3964374]: 209.50.190.194 lemoncreekcampground.ca "Goosee-Audit/1.0 (+internal-security-audit)" sbd-admin:asdf1234 FAIL
...
show less
Brute-Force
Web App Attack
🇫🇷
ELYAZ
2026-06-03 12:09:53
(3 months ago)
(y4) Failed scan -byebye- from 209.50.190.194 (FR/France/-): (CF_ENABLE)
Hacking
🇦🇺
paulshipley.com.au
2026-05-27 23:31:15
(3 months ago)
[Thu May 28 09:31:15.267090 2026] [security2:error] [pid 504468] [client 209.50.190.194:49285] [clie ...
show more
[Thu May 28 09:31:15.267090 2026] [security2:error] [pid 504468] [client 209.50.190.194:49285] [client 209.50.190.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "iaki.com.au"] [uri "/wp-config.bak"] [unique_id "ahd-w-pEZlYv1VhEN8RmpAAAAAc"]
...
show less
Web App Attack
🇦🇺
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
🇺🇸
TPI-Abuse
2026-02-10 01:34:57
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 20:34:48.831425 2026] [security2:error] [pid 1011:tid 1011] [client 209.50.190.194:9693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "khovanov.com"] [uri "/admin/.git/config"] [unique_id "aYqLOJzkq_M-TLYQUgo4qgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 23:01:25
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:01:15.623981 2026] [security2:error] [pid 11233:tid 11233] [client 209.50.190.194:32275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kdeering.net"] [uri "/config/.env"] [unique_id "aYpnO1pJhDVxrWeZWZfwBQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 20:33:18
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:33:12.451860 2026] [security2:error] [pid 12277:tid 12277] [client 209.50.190.194:35293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honeybeeplace.com"] [uri "/api/.git/config"] [unique_id "aYpEiJ3QRdh36VRQVGsBcwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-21 12:07:33
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 07:07:26.791130 2026] [security2:error] [pid 12628:tid 12628] [client 209.50.190.194:47319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radtraininginc.com"] [uri "/.git/HEAD"] [unique_id "aXDBfpdBxorqj_bmB_keUAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-20 23:28:08
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 18:28:04.135002 2026] [security2:error] [pid 1901:tid 1901] [client 209.50.190.194:16423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.svn/wc.db"] [unique_id "aXAPhPpl2gMaTeAPGXZVJwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
myagent.site
2026-01-20 21:48:34
(7 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
🇺🇸
TPI-Abuse
2025-11-24 09:42:13
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:42:05.899089 2025] [security2:error] [pid 18920:tid 18920] [client 209.50.190.194:25097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.neilvboyer.com"] [uri "/.env"] [unique_id "aSQobW232tktN8rKaLsP9QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 08:15:06
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:14:59.159307 2025] [security2:error] [pid 19608:tid 19608] [client 209.50.190.194:52353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "badconsultingllc.com"] [uri "/.svn/wc.db"] [unique_id "aSQUAwIUaZq4cMq-UTISbAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:55:23
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:54:40.067456 2025] [security2:error] [pid 6518:tid 6518] [client 209.50.190.194:24911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fables4teens.banis-associates.com"] [uri "/.git/HEAD"] [unique_id "aSQPQE2oaOu7qRBrGNwWhwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 05:36:49
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:36:44.607271 2025] [security2:error] [pid 3965259:tid 3965338] [client 209.50.190.194:12455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jd-web-designs.com"] [uri "/.svn/wc.db"] [unique_id "aSPu7MHsvdKIeQe-cM9CxwAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack