๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(4 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2025-12-27 22:05:38
(5 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 10:24:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:23:58.554681 2025] [security2:error] [pid 28481:tid 28481] [client 216.26.224.128:46731] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jcsforwarding.com"] [uri "/.svn/wc.db"] [unique_id "aSbVPrlIkc_7Ob4SbdJBJgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:36:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:36:09.090824 2025] [security2:error] [pid 19940:tid 19940] [client 216.26.224.128:10883] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.interforce.com"] [uri "/.svn/wc.db"] [unique_id "aSa7-QZNcdO90RmRq5nnPQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:38:01
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:37:55.270852 2025] [security2:error] [pid 2430343:tid 2430343] [client 216.26.224.128:24765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.strawberryhillchristmas.com"] [uri "/.svn/wc.db"] [unique_id "aSaSM-eetGyP6U1xZ_iIxwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 03:15:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 22:15:54.919378 2025] [security2:error] [pid 7679:tid 7679] [client 216.26.224.128:32493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.walkerscayproductions.com"] [uri "/.svn/wc.db"] [unique_id "aSZw6lv4QZfeV4OcfQPRrgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:42:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:42:42.165806 2025] [security2:error] [pid 23963:tid 23963] [client 216.26.224.128:35175] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.andiamocomputers.com"] [uri "/.env"] [unique_id "aSUJkj_xcXzsRefudtI_lwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:24:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:24:17.862677 2025] [security2:error] [pid 24424:tid 24424] [client 216.26.224.128:22587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.intellian.us"] [uri "/.svn/wc.db"] [unique_id "aST3MU-SPqlU13Gjv-zQzwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:35:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:35:30.102620 2025] [security2:error] [pid 5874:tid 5874] [client 216.26.224.128:41643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.grollman.com"] [uri "/.env"] [unique_id "aSQY0gAOloSMLGgJXFlgOAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 00:18:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 19:18:12.330364 2025] [security2:error] [pid 31601:tid 31601] [client 216.26.224.128:42583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globesportsmanagement.vangentholding.com"] [uri "/.git/HEAD"] [unique_id "aSOkRBgOYa0Ac8IWDJB22gAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-11-19 07:49:10
(6 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-11-13 23:08:46
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-14 15:23:52
(8 months ago)
GlobalProtect login attempts with user bardasis.
VPN IP
Brute-Force
Anonymous
2025-10-14 02:53:54
(8 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force
Anonymous
2025-10-07 17:54:43
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.07 is noted in report timestamp
show less
Hacking
Brute-Force