🇬🇧
gurnip
2026-09-08 02:51:51
(8 hours ago)
Vulnerability probe of page /wp-sitemap.xml, not found on server.
Brute-Force
Web App Attack
🇲🇽
octageeks.com
2026-08-13 04:24:33
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇫🇷
Sklurk
2026-08-05 00:38:54
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-30 01:59:50
(1 month ago)
Web App Attack
Web App Attack
🇬🇧
PeravixGroup
2026-05-07 20:24:29
(4 months ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
🇺🇸
TPI-Abuse
2025-11-26 12:09:54
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 07:09:46.950628 2025] [security2:error] [pid 14117:tid 14117] [client 216.26.242.14:38893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.majersigns.com"] [uri "/.env"] [unique_id "aSbuCvxbvRDE9nICxNlfJwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 10:31:37
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:31:31.197536 2025] [security2:error] [pid 16933:tid 16933] [client 216.26.242.14:38539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.shafie.net"] [uri "/.env"] [unique_id "aSbXA4R7k8M5Z-H7KuYVdAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 08:40:25
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:40:20.592811 2025] [security2:error] [pid 2591955:tid 2591955] [client 216.26.242.14:48655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.texaspropertyinspection.com"] [uri "/.git/HEAD"] [unique_id "aSa89EjKA3PLMzEX22rCGgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2025-11-26 06:43:37
(9 months ago)
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 01:58:51
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:58:44.644985 2025] [security2:error] [pid 27090:tid 27090] [client 216.26.242.14:34605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.serviciodepinturadecasas.com"] [uri "/.git/HEAD"] [unique_id "aSUNVOJeHospkLoEnAsiDgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 09:03:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:02:37.123480 2025] [security2:error] [pid 243933:tid 244019] [client 216.26.242.14:44131] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.inal.org"] [uri "/.env"] [unique_id "aSQfLdmGQHQ5UZm-z0AuTAAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 08:13:58
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:13:53.218533 2025] [security2:error] [pid 6372:tid 6372] [client 216.26.242.14:40611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jsommer.com"] [uri "/.svn/wc.db"] [unique_id "aSQTwWtN-JpPzFfbYcKfbgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack