๐ฉ๐ช
4server
2026-05-07 04:08:20
(1 month ago)
[ThuMay0706:08:16.7954482026][security2:error][pid4059601:tid4059738][client216.26.236.131:0]ModSecu ...
show more
[ThuMay0706:08:16.7954482026][security2:error][pid4059601:tid4059738][client216.26.236.131:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"scrspace.com\"][uri\"/wp-json/gravitysmtp/v1/tests/mock-data\"][unique_id\"afwQMBEalFYqgacf50CS3AAAARE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-05-02 22:14:31
(1 month ago)
Honeypot detection: Memcached unauthorized access / amplification attempt on port 2375. Severity: HI ...
show more
Honeypot detection: Memcached unauthorized access / amplification attempt on port 2375. Severity: HIGH. Aaran.cloud
show less
Hacking
Exploited Host
๐ฉ๐ช
F242
2026-01-30 05:59:57
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฑ๐ป
garmtech.com
2026-01-14 09:05:08
(4 months ago)
IM360 WAF: Attempt to upload malware
Hacking
๐ฎ๐น
main.ows
2025-11-25 18:46:22
(6 months ago)
[25/Nov/2025:19:46:21.491125 +0100] aSX5e1Lstet7peXnuKGttwAAAEM 216.26.236.131 39756 217.61.13.167 7 ...
show more
[25/Nov/2025:19:46:21.491125 +0100] aSX5e1Lstet7peXnuKGttwAAAEM 216.26.236.131 39756 217.61.13.167 7080
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:46:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:46:14.662524 2025] [security2:error] [pid 2854:tid 2854] [client 216.26.236.131:57329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.adj-tech.net"] [uri "/.svn/wc.db"] [unique_id "aSU0ltUTsvL9UV3mfRc6LwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:59:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:59:40.306985 2025] [security2:error] [pid 5311:tid 5311] [client 216.26.236.131:12329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.portraitartisans.com"] [uri "/.env"] [unique_id "aSUprD6cOccjO8Edk7XmMAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:33:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:33:44.676723 2025] [security2:error] [pid 21511:tid 21511] [client 216.26.236.131:15991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kinnairdwoodworking.com"] [uri "/.env"] [unique_id "aSUjmPWn7RMsxHtXEa66RAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:06:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:06:43.727324 2025] [security2:error] [pid 1647141:tid 1647211] [client 216.26.236.131:44417] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.opticaldesignconcepts.com"] [uri "/.git/HEAD"] [unique_id "aSUPM9ffCdpZ5cNrCNdiqgAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:35:13
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:35:07.553174 2025] [security2:error] [pid 16527:tid 16527] [client 216.26.236.131:22845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.batonrougecustomcabinets.com"] [uri "/.svn/wc.db"] [unique_id "aSUHy6lRZn0AVGuUQYVE9gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:01:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:01:12.897122 2025] [security2:error] [pid 8692:tid 8692] [client 216.26.236.131:19767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.flyingwithstan.com"] [uri "/.git/HEAD"] [unique_id "aST_2KRr44gaclrc3c9CdAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:01:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:01:49.254984 2025] [security2:error] [pid 21703:tid 21703] [client 216.26.236.131:24941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.18mstudio.com"] [uri "/.svn/wc.db"] [unique_id "aSTx7bTDqEKZJQtiY3ECLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 07:19:01
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 10:50:09
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 216.26.236.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 06:50:01.100170 2025] [security2:error] [pid 28189:tid 28189] [client 216.26.236.131:24265] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||garanta.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "garanta.co"] [uri "/wp-json/wp/v2/users"] [unique_id "aQXl2TJgxncvUNl3JsxWkQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-16 05:48:00
(7 months ago)
Unauthorized connection attempt
Brute-Force