๐ง๐ช
cmbplf
2026-03-13 01:26:15
(3 months ago)
3.744 requests with url.path */xmlrpc.php
1.812 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(4 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-21 06:24:37
(4 months ago)
(mod_security) mod_security (id:210580) triggered by 216.26.230.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210580) triggered by 216.26.230.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 01:24:29.650916 2026] [security2:error] [pid 23012:tid 23012] [client 216.26.230.99:27641] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:page_id. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||ashwoodsecurity.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:page_id: ../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "ashwoodsecurity.com"] [uri "/"] [unique_id "aXBxHYJHfHc6lfpWicxTpwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Swiptly
2026-01-15 12:24:20
(4 months ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐บ๐ธ
myagent.site
2026-01-15 08:39:15
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-02 18:20:23
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 13:20:17.535743 2026] [security2:error] [pid 30101:tid 30101] [client 216.26.230.99:14045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nmrising.org.peterlundman.com"] [uri "/.svn/wc.db"] [unique_id "aVgMYU8yjpK2JrHOKJsoCQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 06:12:04
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:11:57.689530 2025] [security2:error] [pid 3654:tid 3654] [client 216.26.230.99:18535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gunsforukraine.com"] [uri "/.git/HEAD"] [unique_id "aVIbreimMkRk4K7wpCWMxwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:35:44
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.230.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.230.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:35:37.916436 2025] [security2:error] [pid 30144:tid 30144] [client 216.26.230.99:32235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qwik-wash.com"] [uri "/.env"] [unique_id "aVIFGaPl4D7rNyS_BU8pOgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2025-12-27 13:45:08
(5 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-11-19 07:55:42
(6 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-11-14 05:06:47
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-29 05:02:39
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-05 18:15:51
(8 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.05 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-04 07:21:10
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.04 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.04 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-09-28 22:36:40
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.28 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.28 is noted in report timestamp
show less
Hacking
Brute-Force