🇫🇷
Sklurk
2026-08-09 00:04:48
(2 weeks ago)
Web App Attack
Web App Attack
🇺🇸
cwytech
2026-07-27 18:33:03
(1 month ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
🇩🇪
F242
2026-01-30 05:15:26
(6 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-01-21 13:43:11
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 08:43:07.470766 2026] [security2:error] [pid 22568:tid 22568] [client 216.26.248.130:47061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "impostersyndromeunmasked.com"] [uri "/.svn/wc.db"] [unique_id "aXDX6yxYwokWFZ22newSYAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
iNetWorker
2026-01-21 11:13:46
(7 months ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-01-21 10:56:18
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 05:56:13.463453 2026] [security2:error] [pid 11267:tid 11267] [client 216.26.248.130:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sportsbookcommission.com"] [uri "/.git/HEAD"] [unique_id "aXCwzct9TzJ_wyZT38ye3gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-21 00:40:36
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 19:40:11.073326 2026] [security2:error] [pid 909489:tid 909500] [client 216.26.248.130:51689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gotogps.com"] [uri "/.svn/wc.db"] [unique_id "aXAga2Rn1e3-B0EzQfVsvQAAAgg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
10dencehispahard SL
2026-01-20 06:49:54
(7 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
🇱🇻
garmtech.com
2026-01-10 09:29:48
(7 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
🇺🇸
TPI-Abuse
2025-12-30 18:36:05
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 13:35:19.209472 2025] [security2:error] [pid 28723:tid 28723] [client 216.26.248.130:54129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lsd36.com"] [uri "/.svn/wc.db"] [unique_id "aVQbZ0BXjJ80CWwHQ9mkFQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 04:00:25
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:00:20.173284 2025] [security2:error] [pid 7422:tid 7422] [client 216.26.248.130:16455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wexfordcap.com"] [uri "/.env"] [unique_id "aVH81EmQjf_6MItcM1qj_wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-07 10:04:49
(9 months ago)
[redacted] 216.26.248.130 - - [07/Nov/2025:11:04:29 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" " ...
show more
[redacted] 216.26.248.130 - - [07/Nov/2025:11:04:29 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419.3 (KHTML, like Gecko) Safari/419.3"
[redacted] 216.26.248.130 - - [07/Nov/2025:11:04:31 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Linux; Android 8.0.0; FIG-LX3 Build/HUAWEIFIG-LX3; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/69.0.3497.100 Mobile Safari/537.36 [FB_IAB/FB4A;FBAV/191.0.0.35.96;]"
[redacted] 216.26.248.130 - - [07/Nov/2025:11:04:33 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_0_2 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/14A456 Safari/602.1"
[redacted] 216.26.248.130 - - [07/Nov/2025:11:04:35 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (iPad; CPU OS 7_1 like Mac OS X) AppleWebKit/537.51.2 (KHTML, like Gecko) Version/7.0 Mobile/11D167 Safari/9537.53"
pjwasserma
...
show less
Hacking
Web App Attack
Anonymous
2025-10-16 10:31:19
(10 months ago)
Bad Web Bot
Web App Attack