๐ฌ๐ง
PeravixGroup
2026-05-27 21:31:20
(1 week ago)
Honeypot detection: FTP brute-force or anonymous access attempt on port 21. Severity: MEDIUM. Aaran. ...
show more
Honeypot detection: FTP brute-force or anonymous access attempt on port 21. Severity: MEDIUM. Aaran.cloud
show less
FTP Brute-Force
Brute-Force
๐ฉ๐ช
4server
2026-05-13 15:38:59
(3 weeks ago)
[WedMay1317:38:53.3050192026][security2:error][pid1883130:tid1883203][client216.26.250.176:0]ModSecu ...
show more
[WedMay1317:38:53.3050192026][security2:error][pid1883130:tid1883203][client216.26.250.176:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.dellafoglia.ch.136-243-54-122.cpanel.site\"][uri\"/wp-json/gravitysmtp/v1/tests/mock-data\"][unique_id\"agSbDVI1Derrpa5xslEU6gAAAIs\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-04-02 21:38:10
(2 months ago)
5.320 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-20 14:31:13
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 09:31:10.168886 2026] [security2:error] [pid 26994:tid 26994] [client 216.26.250.176:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||caspina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "caspina.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZhwLiRuhV1vBX8kLUg-2gAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:29
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-25 06:42:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:41:59.886047 2025] [security2:error] [pid 24589:tid 24589] [client 216.26.250.176:19169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.myrtlebeachpartybuses.com"] [uri "/.svn/wc.db"] [unique_id "aSVPtyK-QxHRxuvoY9CvzgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:57:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:57:36.779607 2025] [security2:error] [pid 1943:tid 1943] [client 216.26.250.176:17325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lordhari.com"] [uri "/.git/HEAD"] [unique_id "aSQsEBHHByruikuySO_lSgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:30:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:30:10.844035 2025] [security2:error] [pid 15772:tid 15772] [client 216.26.250.176:53021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.phantomkennels.com"] [uri "/.svn/wc.db"] [unique_id "aSQXkp9kn5IPLn0GXsHDLAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:38:16
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:38:13.157608 2025] [security2:error] [pid 27380:tid 27380] [client 216.26.250.176:40821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "athome360.com"] [uri "/.svn/wc.db"] [unique_id "aSQLZb00X9bzKTRY3hF9zgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:25:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:25:22.375826 2025] [security2:error] [pid 14843:tid 14863] [client 216.26.250.176:9069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gochemless.com"] [uri "/.svn/wc.db"] [unique_id "aSPeMl0D_Mes39tIl2r3NwAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 18:56:36
(6 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/13 12:55:16
Port Scan
Brute-Force
Exploited Host
Web App Attack