๐ณ๐ฟ
billyborsht
2026-08-30 21:52:53
(1 day ago)
2026-08-31T09:52:52.732122+12:00 southern wordpress(nzangels.com)[1420398]: Authentication attempt f ...
show more
2026-08-31T09:52:52.732122+12:00 southern wordpress(nzangels.com)[1420398]: Authentication attempt for unknown user seobackup from 216.26.248.33
...
show less
Hacking
Web App Attack
๐บ๐ธ
Penny Packer
2026-08-12 08:06:23
(2 weeks ago)
Fail2Ban apache-404
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-05-31 22:58:41
(3 months ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐ง๐ช
cmbplf
2026-05-31 04:23:55
(3 months ago)
443 requests with url.path */.git/config
443 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-05-31 04:05:39
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
Anonymous
2026-05-31 03:29:08
(3 months ago)
216.26.248.33 - - [31/May/2026:11:29:07 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
216.26.248.33 - - [31/May/2026:11:29:07 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-05-31 03:04:57
(3 months ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-31 02:27:56
(3 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 216.26.248.33 (TH/Thailand/-): 2 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 216.26.248.33 (TH/Thailand/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 18:32:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 14:32:24.085851 2026] [security2:error] [pid 15842:tid 15842] [client 216.26.248.33:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swarnar.com"] [uri "/.env"] [unique_id "afeUuOl-qDY0ai3tl7_OvQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-24 10:14:16
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 24 05:14:10.450227 2026] [security2:error] [pid 6118:tid 6118] [client 216.26.248.33:16909] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||havelocktruckandauto.ca|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "havelocktruckandauto.ca"] [uri "/2024.db"] [unique_id "aXSbcp0kG349vR-w7IyRXwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-12-03 07:58:37
(8 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-11-28 13:24:07
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 08:24:03.043063 2025] [security2:error] [pid 6834:tid 6834] [client 216.26.248.33:9397] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amatosdrywall.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amatosdrywall.com"] [uri "/backup.sql"] [unique_id "aSmic5NEsEABjsTKRXSZewAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:45:29
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:45:20.259100 2025] [security2:error] [pid 16934:tid 16982] [client 216.26.248.33:40849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.seracon.com.ec"] [uri "/.git/HEAD"] [unique_id "aSaT8BKESCEx-WKRVnsm3AAAAZI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 03:00:00
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:59:54.055117 2025] [security2:error] [pid 15470:tid 15470] [client 216.26.248.33:16541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.reunionking.com"] [uri "/.svn/wc.db"] [unique_id "aSZtKj7fQYQ4h040t8VU4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:26:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:26:26.811849 2025] [security2:error] [pid 2018:tid 2018] [client 216.26.248.33:23545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.insearchofgod.org"] [uri "/.svn/wc.db"] [unique_id "aSZXQhUSmuo-95vHxstSzgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack