🇺🇸
Charlesiv
2026-09-02 20:02:59
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 200373 (3xK Tech GmbH)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 200373 (3xK Tech GmbH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /xmlrpc.php
Timestamp: 2026-09-02T19:32:54Z
Ray ID: a34ef1815a4f97b9
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
Bad Web Bot
🇺🇸
lostswordfish.com
2026-08-31 13:10:04
(1 week ago)
Wordfence waf block on pameganslaw
Web App Attack
🇩🇪
conseilgouz
2026-08-31 07:29:34
(1 week ago)
sle-6 : Trying access system files=>/wp-login.php(wp-login.php)
Hacking
🇫🇷
ELYAZ
2026-08-30 05:54:19
(1 week ago)
(wordpress) Failed wordpress login from 216.26.239.12 (BR/Brazil/-): (CF_ENABLE)
Brute-Force
🇩🇪
F242
2026-08-29 19:48:45
(1 week ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇫🇷
Sklurk
2026-08-02 01:17:34
(1 month ago)
Web App Attack
Web App Attack
🇩🇪
bontekoe.technology
2025-12-28 16:00:30
(8 months ago)
Port scan or Brute-Force detected. (src_port=23227, dst_port=80)
Brute-Force
🇺🇸
TPI-Abuse
2025-12-28 15:47:29
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 10:47:21.760930 2025] [security2:error] [pid 30958:tid 30958] [client 216.26.239.12:53153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thinksite.com"] [uri "/.env"] [unique_id "aVFRCRf_kyDZxk-vmd6pAgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-08 01:27:26
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 20:27:18.352059 2025] [security2:error] [pid 902:tid 926] [client 216.26.239.12:35825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iamfluff.com"] [uri "/.git/HEAD"] [unique_id "aTYpdr71iYNayHGevDZttAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 14:13:40
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 09:13:36.766897 2025] [security2:error] [pid 15946:tid 15946] [client 216.26.239.12:47683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrpinman.org"] [uri "/.env"] [unique_id "aTWLkPWPjOn1dgeJgPXymQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 13:22:01
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 08:21:57.301813 2025] [security2:error] [pid 18364:tid 18364] [client 216.26.239.12:17633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldcountrygermanamericanclub.org"] [uri "/.git/HEAD"] [unique_id "aTV_ddGlWcEUX46kd1EObwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-05 06:00:07
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 01:00:02.267507 2025] [security2:error] [pid 20925:tid 20925] [client 216.26.239.12:45423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dorismitchell.com"] [uri "/.svn/wc.db"] [unique_id "aTJ04qCuF5pyx_mofBdTlgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-05 00:27:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 19:27:01.281343 2025] [security2:error] [pid 6203:tid 6203] [client 216.26.239.12:14107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oficinasydespachosmurcia.com"] [uri "/.env"] [unique_id "aTIm1QMv-oBmUIf7hdavkQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-05 00:10:25
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 19:10:21.451649 2025] [security2:error] [pid 8917:tid 8931] [client 216.26.239.12:57409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artisancutgemstones.com"] [uri "/.svn/wc.db"] [unique_id "aTIi7brc5ipWQk-c8MKu0gAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
oncord
2025-11-21 18:44:56
(9 months ago)
Form spam
Web Spam