🇩🇪
F242
2026-08-29 19:49:43
(9 hours ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇩🇪
conseilgouz
2026-08-22 17:19:46
(1 week ago)
mae-6 : Trying access system files=>/wp-login.php(wp-login.php)
Hacking
🇩🇪
FeG Deutschland
2026-08-21 23:32:16
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 23:26:56
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 18:26:50.424780 2025] [security2:error] [pid 2277:tid 2277] [client 216.26.240.63:35575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onerealonboarding.com"] [uri "/.svn/wc.db"] [unique_id "aToBulK_5a8qYrZxen6yuwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 22:56:19
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 17:56:12.027633 2025] [security2:error] [pid 20296:tid 20296] [client 216.26.240.63:32767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "memorialcityzen.com"] [uri "/.env"] [unique_id "aTYGDMdOIvpGzdRvkkGJiQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 14:54:27
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 09:54:19.206629 2025] [security2:error] [pid 27962:tid 27962] [client 216.26.240.63:26293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salinabible.org"] [uri "/.git/HEAD"] [unique_id "aTWVG6_lldBT78L5olxfyQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 14:01:26
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 09:01:18.667774 2025] [security2:error] [pid 11755:tid 11755] [client 216.26.240.63:55917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lurye.org"] [uri "/.env"] [unique_id "aTWIrlBcamr1u5wD8fdpDAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 12:35:17
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 07:35:13.015406 2025] [security2:error] [pid 30665:tid 30665] [client 216.26.240.63:21169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carpentersbattery.org"] [uri "/.env"] [unique_id "aTV0gQlJRwA3ssFXrLz8EQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
myagent.site
2025-12-06 17:08:03
(8 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
🇺🇸
TPI-Abuse
2025-12-05 05:43:17
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 00:43:11.892407 2025] [security2:error] [pid 8020:tid 8028] [client 216.26.240.63:13653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mandhco.com"] [uri "/.env"] [unique_id "aTJw75sJP7QP_uYcdsbpKQAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-05 01:23:59
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.240.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 20:23:29.396013 2025] [security2:error] [pid 27809:tid 27809] [client 216.26.240.63:40107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "plazahacienda.com"] [uri "/.svn/wc.db"] [unique_id "aTI0EfZr-dle2R9-DP9JOwAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2025-10-30 20:28:40
(9 months ago)
995 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot