๐บ๐ธ
LSPCCU
2026-06-14 23:29:47
(3 days ago)
TSEC Honeypot Network report. Threat score: 70/100. Categories: Hacking. Honeypot: ssh-telnet, cowri ...
show more
TSEC Honeypot Network report. Threat score: 70/100. Categories: Hacking. Honeypot: ssh-telnet, cowrie. Context: 216.
show less
Hacking
๐ณ๐ฑ
soverin
2026-05-21 21:26:28
(3 weeks ago)
Network scan on port 443
Email Spam
๐บ๐ธ
TPI-Abuse
2026-01-17 08:11:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 03:11:50.473286 2026] [security2:error] [pid 30172:tid 30172] [client 216.26.230.29:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eddysgroup.com"] [uri "/.env"] [unique_id "aWtERnzt9pSnb8aA9bRUXQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 06:21:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 01:20:55.096087 2026] [security2:error] [pid 21601:tid 21601] [client 216.26.230.29:53683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.donutburger.com"] [uri "/.env"] [unique_id "aWsqR-SNCzx2oZFAlBVR6AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 05:12:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 00:12:35.191060 2026] [security2:error] [pid 6716:tid 6716] [client 216.26.230.29:24383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.majesticsolutions.co"] [uri "/.env"] [unique_id "aWsaQ8T17DF3-tTnXohS7wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-22 21:38:53
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
Anonymous
2025-12-16 08:11:16
(6 months ago)
botnet
DDoS Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-30 13:09:48
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-24 06:42:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:42:35.063179 2025] [security2:error] [pid 23683:tid 23683] [client 216.26.230.29:13395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aufflammen.com"] [uri "/.git/HEAD"] [unique_id "aSP-W58CC6z-Tam1xoCBOgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:41:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:41:44.602169 2025] [security2:error] [pid 17835:tid 17835] [client 216.26.230.29:54533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.luciferdirective.com"] [uri "/.svn/wc.db"] [unique_id "aSPwGFUMTxFrkmPq97If4AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:01:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:01:24.315597 2025] [security2:error] [pid 23385:tid 23385] [client 216.26.230.29:28929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cureforcancerbook.com"] [uri "/.git/HEAD"] [unique_id "aSPmpODa_EbgHcEyg2RfegAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:31:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:31:22.435090 2025] [security2:error] [pid 31069:tid 31069] [client 216.26.230.29:12615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wethepeoplealliance.org"] [uri "/.svn/wc.db"] [unique_id "aSPfmpefEfX-vDbulldxVwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 22:02:25
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-16 00:33:41
(8 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.16 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.16 is noted in report timestamp
show less
Hacking
Brute-Force
๐จ๐ฆ
wil.com
2025-10-15 14:42:56
(8 months ago)
GlobalProtect login attempts with user liebnerk.
VPN IP
Brute-Force