๐ซ๐ท
Sklurk
2026-07-29 02:52:54
(7 hours ago)
Web App Attack
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-28 12:26:04
(21 hours ago)
Wordfence waf block on baystatereentrynetwork
Web App Attack
๐ซ๐ท
ELYAZ
2026-07-28 02:38:19
(1 day ago)
(wordpress) Failed wordpress login from 216.26.227.40 (US/United States/-): (CF_ENABLE)
Brute-Force
๐ซ๐ท
Sklurk
2026-07-16 09:46:59
(1 week ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-07 16:27:52
(3 weeks ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-06-23 03:57:13
(1 month ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-06-20 00:17:58
(1 month ago)
Web App Attack
Web App Attack
๐ฉ๐ช
F242
2026-01-30 05:39:20
(5 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:21:33
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:21:22.871376 2025] [security2:error] [pid 6008:tid 6008] [client 216.26.227.40:9355] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.genevaatlantic.com"] [uri "/.env"] [unique_id "aSQjkha-3mQFHS4y1Lw0jgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:57:53
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:57:47.467867 2025] [security2:error] [pid 22832:tid 22832] [client 216.26.227.40:38643] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ottocustoms.g-h2o.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ottocustoms.g-h2o.com"] [uri "/.svn/wc.db"] [unique_id "aSPz2-Qf-WvFdOU9ho3XCQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:29:53
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:29:46.055938 2025] [security2:error] [pid 6396:tid 6396] [client 216.26.227.40:60865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.patanthony.com"] [uri "/.svn/wc.db"] [unique_id "aSPfOpG-rW-2C4FW1bOZ-gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:13:45
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:13:39.559724 2025] [security2:error] [pid 3276564:tid 3276564] [client 216.26.227.40:25351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wilburmanagementgroup.com"] [uri "/.env"] [unique_id "aSPbczWipROMK-KhyCl24wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 03:34:34
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:34:27.251130 2025] [security2:error] [pid 3944521:tid 3944668] [client 216.26.227.40:14563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.securitymediaservices.com"] [uri "/.git/HEAD"] [unique_id "aSPSQ-_Sh5gQdv9DIAk4VgAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 16:59:13
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.227.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 11:59:06.227615 2025] [security2:error] [pid 5410:tid 5410] [client 216.26.227.40:59717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tgcindustrial.com"] [uri "/.env"] [unique_id "aRtUWp6F0rWw5YARm38BQwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 22:04:26
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack