🇫🇷
Sklurk
2026-08-03 03:12:33
(3 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-08-02 01:56:33
(4 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-30 00:41:47
(1 month ago)
Web App Attack
Web App Attack
🇩🇪
Mr-Money
2026-03-26 23:59:42
(5 months ago)
scenario: crowdsecurity/http-sensitive-files - events: 5
Web App Attack
Hacking
🇨🇭
backslash
2026-01-05 01:45:05
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇮🇹
VHosting
2026-01-04 06:55:03
(7 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 07:06:49
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:06:42.316873 2025] [security2:error] [pid 28229:tid 28229] [client 216.26.248.43:35269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "left-hander.com"] [uri "/.git/HEAD"] [unique_id "aS6QAtlWD_mU-WAugqtySAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 04:59:27
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:59:20.313375 2025] [security2:error] [pid 9529:tid 9529] [client 216.26.248.43:52719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "meganmurph.com"] [uri "/.git/HEAD"] [unique_id "aS5yKEidScco8pAs2qgRyAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 01:12:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 20:12:13.054966 2025] [security2:error] [pid 16001:tid 16001] [client 216.26.248.43:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samos.bet"] [uri "/.git/HEAD"] [unique_id "aS487e7oKKVJJPrRy8ZZUwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:49:47
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:48:59.410622 2025] [security2:error] [pid 21044:tid 21044] [client 216.26.248.43:22173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.desertdwellings.com"] [uri "/.svn/wc.db"] [unique_id "aSQN67sBcj4WbKFPNk_V6gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:37:26
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:37:14.881786 2025] [security2:error] [pid 27627:tid 27627] [client 216.26.248.43:24519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.micahgartman.com"] [uri "/.env"] [unique_id "aSP9GsRTO688VeVx3bLeKgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 04:35:26
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:35:22.666134 2025] [security2:error] [pid 7175:tid 7175] [client 216.26.248.43:37903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.catking.net"] [uri "/.env"] [unique_id "aSPgim0_kWMlzErWW-AHPAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-10 13:51:56
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.26.248.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 08:51:48.695178 2025] [security2:error] [pid 880:tid 880] [client 216.26.248.43:15361] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.sinko-intl.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.sinko-intl.com"] [uri "/s3cmd.ini"] [unique_id "aRHt9AbtiCoDJ0P0aPIv-gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack