🇸🇪
shab
2026-09-03 09:45:58
(18 hours ago)
Suspicious VPN activity
Brute-Force
🇩🇪
Admins@FBN
2026-09-03 02:33:43
(1 day ago)
VPN Logon Failed: AAA user authentication Rejected user = <pvasavd>
Brute-Force
Exploited Host
🇫🇷
Sklurk
2026-08-11 02:56:22
(3 weeks ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 03:50:53
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 22:50:50.297564 2025] [security2:error] [pid 1162:tid 1162] [client 216.26.242.166:35141] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aSZ5Gm1G0aOUtPhjArDbMgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kjaerulff
2025-11-26 01:03:12
(9 months ago)
Failed Wordpress login using xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 05:26:05
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:25:58.836930 2025] [security2:error] [pid 13895:tid 13905] [client 216.26.242.166:51879] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.josephablumphotography.com"] [uri "/.env"] [unique_id "aSU95sqATJ-N2rrGOLaK4QAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 04:56:42
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:56:38.274270 2025] [security2:error] [pid 15023:tid 15023] [client 216.26.242.166:50873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.trixieotoole.com"] [uri "/.env"] [unique_id "aSU3Bj5WZU1QdFcSiNIUaAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 04:28:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:28:25.220490 2025] [security2:error] [pid 29058:tid 29058] [client 216.26.242.166:25055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ibiocat.com"] [uri "/.git/HEAD"] [unique_id "aSUwaT282WzpnDEXrr9Q-wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 04:05:42
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:05:34.431720 2025] [security2:error] [pid 20618:tid 20618] [client 216.26.242.166:27903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.javathecup.com"] [uri "/.env"] [unique_id "aSUrDipVoeNkeHgDfjk4ugAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 03:22:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:22:22.764500 2025] [security2:error] [pid 4679:tid 4679] [client 216.26.242.166:19187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jperverseincentives.com"] [uri "/.git/HEAD"] [unique_id "aSUg7hxfAE9KufoVQLQw7wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 02:58:16
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:58:10.155674 2025] [security2:error] [pid 22632:tid 22632] [client 216.26.242.166:26661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.alexscollay.com"] [uri "/.env"] [unique_id "aSUbQjh9nqK3OZNAWtskbwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 00:32:43
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:32:40.680686 2025] [security2:error] [pid 8306:tid 8306] [client 216.26.242.166:10031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rohn.com"] [uri "/.git/HEAD"] [unique_id "aST5KEiHlPVkeZOE3V1omQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2025-11-03 07:02:27
(10 months ago)
Web App Attack
Web App Attack
🇧🇾
lns.bz
2025-10-17 05:20:11
(10 months ago)
Web app attack [BY]
SSH