๐น๐ท
neron
2026-07-31 09:06:18
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-28 10:19:38
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ซ๐ท
Sklurk
2026-07-17 09:59:52
(1 month ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-09 00:07:39
(1 month ago)
Web App Attack
Web App Attack
๐บ๐ธ
mnsf
2026-06-10 00:09:57
(2 months ago)
Scanning/Probing (34)
Brute-Force
Web App Attack
๐ฌ๐ง
Oakley
2026-04-15 12:25:39
(4 months ago)
(antiscrape_rule) Web application abuse detected 216.26.238.20 (US/United States/-): 5 in the last 9 ...
show more
(antiscrape_rule) Web application abuse detected 216.26.238.20 (US/United States/-): 5 in the last 900 secs
show less
Hacking
Anonymous
2026-03-10 20:22:30
(5 months ago)
VILICO WEBFORM SPAM 216.26.238.20 (216.26.238.20)
Web Spam
๐ฉ๐ช
F242
2026-01-30 05:18:56
(7 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:05
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-02 20:07:57
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 15:07:54.725073 2025] [security2:error] [pid 3420:tid 3434] [client 216.26.238.20:49675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "woofnrose.com"] [uri "/.env"] [unique_id "aS9HGtpYnVkZuI2SUNMRngAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
ai_sucks
2025-12-02 11:03:29
(8 months ago)
Credential scanner
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-02 08:19:11
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 03:19:04.074912 2025] [security2:error] [pid 28200:tid 28200] [client 216.26.238.20:47089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "areafinancieratf.com"] [uri "/.git/HEAD"] [unique_id "aS6g-Ew02sLfE44ZrKaawgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 13:58:41
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 08:58:35.618458 2025] [security2:error] [pid 29754:tid 29754] [client 216.26.238.20:50323] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mitchellamazing.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mitchellamazing.com"] [uri "/backup.sql"] [unique_id "aSmqi8l_YjhBk4MyTxfD1QAAAA0"], referer: http://amazingsteelballast.com/backup.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 13:34:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 08:34:45.493406 2025] [security2:error] [pid 15267:tid 15267] [client 216.26.238.20:19281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazeconsultants.org"] [uri "/wp-config.php.bak"] [unique_id "aSmk9RhV9oFFZwDiy2aBDgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 06:44:05
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:43:59.139768 2025] [security2:error] [pid 25782:tid 25782] [client 216.26.238.20:13561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.shirtzz.com"] [uri "/.env"] [unique_id "aSahr3o5z3x3GaDY8P2OKQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack