Anonymous
2026-04-24 10:02:42
(1 month ago)
wordpress authentication brute force
Brute-Force
Web App Attack
๐ฉ๐ช
F242
2026-01-30 05:13:23
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:24
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-11-25 19:00:40
(6 months ago)
(mod_security) mod_security (id:930130) triggered by 216.26.239.54 (BR/Brazil/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:930130) triggered by 216.26.239.54 (BR/Brazil/-): 1 in the last 3600 secs
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-25 06:28:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:28:24.837352 2025] [security2:error] [pid 23347:tid 23347] [client 216.26.239.54:36909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vtmooses.us"] [uri "/.env"] [unique_id "aSVMiBqJMbh6tnBrywmu5QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:10:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:10:28.990789 2025] [security2:error] [pid 19710:tid 19710] [client 216.26.239.54:22013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.teamadventurecny.com"] [uri "/.git/HEAD"] [unique_id "aSU6ROpRKJN-FCWp2ZCEogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:41:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:40:46.143419 2025] [security2:error] [pid 6661:tid 6661] [client 216.26.239.54:42943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oscarssons.com"] [uri "/.git/HEAD"] [unique_id "aSUzTsyjD7F1xeYPoog7mgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:15:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:15:09.438880 2025] [security2:error] [pid 1817001:tid 1817051] [client 216.26.239.54:55547] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.conservativedemocrat.com"] [uri "/.env"] [unique_id "aSUtTWR1ttxeyDpsCa9QSgAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Carsten
2025-11-25 03:58:53
(6 months ago)
GET [.git/HEAD]
Port Scan
๐บ๐ธ
TPI-Abuse
2025-11-25 03:58:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:58:45.413025 2025] [security2:error] [pid 8227:tid 8227] [client 216.26.239.54:38427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ifblawyers.com"] [uri "/.git/HEAD"] [unique_id "aSUpddD_NI0JDmJsoQRcdAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:39:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:39:29.944575 2025] [security2:error] [pid 27727:tid 27747] [client 216.26.239.54:42593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.metrobaselexpoforum.org"] [uri "/.git/HEAD"] [unique_id "aSUW4feXMnwYTnmV60PWvwAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:02:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:02:21.363738 2025] [security2:error] [pid 23518:tid 23518] [client 216.26.239.54:44907] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wardellbrown.com"] [uri "/.env"] [unique_id "aSUOLdDX146P27Q_qattBAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:37:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:37:22.757715 2025] [security2:error] [pid 30902:tid 30902] [client 216.26.239.54:59623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bryteandbroderick.webserviceswest.com"] [uri "/.env"] [unique_id "aSUIUm2fM6SxHsfa-Z8aFwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:13:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:13:26.139100 2025] [security2:error] [pid 10231:tid 10231] [client 216.26.239.54:21063] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.styxwetworld.com"] [uri "/.svn/wc.db"] [unique_id "aSUCtsUNvjeS9tTM8inv-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-02 14:39:29
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 07:10:14
Port Scan
Brute-Force
Exploited Host
Web App Attack