🇺🇸
SX Communications
2026-09-04 11:14:39
(19 hours ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 216.26.224.26: traffic from this ad ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 216.26.224.26: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
🇩🇪
NxtGenIT
2026-09-04 02:25:20
(1 day ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html HTTP/1.1" 302 -,
Brute-Force
🇨🇿
lp
2026-09-03 18:21:15
(1 day ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 216.26.224.26
2026-09-03T19:59:12+02: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 216.26.224.26
2026-09-03T19:59:12+02:00 vpn Access-Reject 'carla' station: 216.26.224.26 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T20:00:43+02:00 vpn Access-Reject 'tab' station: 216.26.224.26 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇪🇸
librebit
2026-09-02 02:50:41
(3 days ago)
Brute force
Brute-Force
🇫🇷
Sklurk
2026-08-01 01:41:28
(1 month ago)
Web App Attack
Web App Attack
🇱🇻
garmtech.com
2026-03-15 17:00:11
(5 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
🇺🇸
TPI-Abuse
2026-01-15 01:49:01
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 20:48:53.942161 2026] [security2:error] [pid 11814:tid 11814] [client 216.26.224.26:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/.env"] [unique_id "aWhHhY7yiARkeghhpVgQbQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-01-14 22:50:34
(7 months ago)
Kingcopy(AI-IDS):IP does Multiple AWS Environment Abuse
Hacking
Web App Attack
Anonymous
2025-12-01 05:42:36
(9 months ago)
botnet
DDoS Attack
🇫🇷
service Informatique
2025-11-26 04:00:37
(9 months ago)
GET /.svn
Web App Attack
🇬🇧
essinghigh
2025-11-25 05:16:58
(9 months ago)
IPS Detection: 216.26.224.26 -> DPT: 80
Port Scan
🇺🇸
TPI-Abuse
2025-11-25 04:24:10
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:24:04.503341 2025] [security2:error] [pid 15743:tid 15743] [client 216.26.224.26:29159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "resume.marat.info"] [uri "/.env"] [unique_id "aSUvZALGvV9DdxgAFvJJBwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 03:49:08
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:48:59.649808 2025] [security2:error] [pid 32347:tid 32347] [client 216.26.224.26:30269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jeffreycopeland.com"] [uri "/.git/HEAD"] [unique_id "aSUnK_k3_8eLncPEj0n_lgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 03:19:17
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:19:13.635876 2025] [security2:error] [pid 23324:tid 23324] [client 216.26.224.26:58301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flugstad.com"] [uri "/.env"] [unique_id "aSUgMbBm1vCHggdZAnTX2gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 02:03:25
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.224.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:03:20.026347 2025] [security2:error] [pid 31498:tid 31519] [client 216.26.224.26:32631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alexlogic.com"] [uri "/.svn/wc.db"] [unique_id "aSUOaPow9dE5SYd00VRa_QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack