๐ซ๐ท
Sklurk
2026-09-05 12:15:05
(3 weeks ago)
Web App Attack
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-09-05 01:22:31
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus D ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus DROP Listed Traffic Inbound group 68).
show less
Hacking
Web App Attack
๐จ๐ฟ
lp
2026-09-04 06:21:42
(3 weeks ago)
Unauthorized VPN login attempts: 6 attempts were recorded from 216.26.242.164
2026-09-04T08:00:39+02 ...
show more
Unauthorized VPN login attempts: 6 attempts were recorded from 216.26.242.164
2026-09-04T08:00:39+02:00 vpn Access-Reject 'spencer' station: 216.26.242.164 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T08:02:12+02:00 vpn Access-Reject 'simon' station: 216.26.242.164 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T08:05:54+02:00 vpn Access-Reject 'natalie' station: 216.26.242.164 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T08:07:43+02:00 vpn Access-Reject 'dev' station: 216.26.242.164 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T08:09:33+02:00 vpn Access-Reject 'mike-pc' station: 216.26.242.164 auth-type: - realm: vse.cz nas: <reda
show less
Brute-Force
Web App Attack
๐ธ๐ช
OnTheEdge
2026-09-03 11:14:41
(3 weeks ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐บ๐ธ
drewf.ink
2026-09-01 10:27:48
(4 weeks ago)
[10:27] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[10:27] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
๐บ๐ธ
drewf.ink
2026-08-31 19:35:18
(4 weeks ago)
[19:35] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[19:35] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
๐ซ๐ท
Sklurk
2026-07-30 02:11:50
(2 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
cwytech
2026-07-27 18:33:02
(2 months ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-01-06 10:00:14
(8 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2025-12-29 10:05:48
(9 months ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2025-12-28 14:46:58
(9 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:53:43
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:53:36.745942 2025] [security2:error] [pid 4483:tid 4483] [client 216.26.242.164:33169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.genevainvestors.internetnameregistration.com"] [uri "/.svn/wc.db"] [unique_id "aSbAENpTNKwN5tZHx7ofRQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 06:37:13
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:37:08.222004 2025] [security2:error] [pid 19451:tid 19451] [client 216.26.242.164:42673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.marilynmonroebookshop.com"] [uri "/.svn/wc.db"] [unique_id "aSagFM_CElA7i3GnMu_uYAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:52:39
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:52:33.534877 2025] [security2:error] [pid 15333:tid 15333] [client 216.26.242.164:52451] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bhsp.org"] [uri "/.svn/wc.db"] [unique_id "aSaVoe5esg4VMC65i-488wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 02:57:41
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:57:34.374121 2025] [security2:error] [pid 18046:tid 18046] [client 216.26.242.164:53535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.businessimagination.com"] [uri "/.env"] [unique_id "aSZsnh6Vhc_KlQtPB6j2TgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack