๐ซ๐ท
ELYAZ
2026-06-24 07:21:08
(2 days ago)
(y4) Failed scan -byebye- from 216.26.254.193 (FR/France/-): (CF_ENABLE)
Hacking
๐ฑ๐ป
garmtech.com
2026-06-24 02:49:13
(2 days ago)
IM360 WAF: Prohibited WordPress username login/registration
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-21 10:44:02
(5 days ago)
(y4) Failed scan -byebye- from 216.26.254.193 (FR/France/-): (CF_ENABLE)
Hacking
๐ฆ๐บ
HJ5Ss4Ju
2026-06-20 10:10:05
(6 days ago)
Blocked by Wordfence (SID 6)
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-20 04:25:26
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฌ๐ท
setupgr
2026-06-19 00:00:10
(1 week ago)
(mod_security) mod_security (id:900001) triggered by 216.26.254.193 (FR/France/รยle-de-France/Paris/ ...
show more
(mod_security) mod_security (id:900001) triggered by 216.26.254.193 (FR/France/รยle-de-France/Paris/-/[AS200373 DREI-K-TECH-GMBH]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Fri Jun 19 03:00:01.782968 2026] [security2:error] [pid 2276:tid 2349] [client 216.26.254.193:40283] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "75"] [id "900001"] [msg "Blocked WP Login attempt on domain: babis.photo"] [severity "CRITICAL"] [tag "security"] [hostname "babis.photo"] [uri "/wp-login.php"] [unique_id "ajSGgfFOzdhEIc8u07di2AAAAAU"], referer: https://babis.photo/wp-login.php
show less
Port Scan
๐ฉ๐ช
iNetWorker
2026-06-18 14:13:49
(1 week ago)
trolling for resource vulnerabilities
Web App Attack
๐ฒ๐น
Malta
2026-06-16 12:17:12
(1 week ago)
216.26.254.193 - - [16/Jun/2026:14:17:12 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintos ...
show more
216.26.254.193 - - [16/Jun/2026:14:17:12 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-16 05:26:16
(1 week ago)
(y4) Failed scan -byebye- from 216.26.254.193 (FR/France/-): (CF_ENABLE)
Hacking
๐ฉ๐ช
piticu iuli
2026-03-02 22:00:06
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 216.26.254.193 (FR/France/-)
SQL Injection
Anonymous
2026-01-03 13:42:12
(5 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.03 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.03 is noted in report timestamp
show less
Hacking
Brute-Force
๐จ๐ณ
ThreatBook.io
2025-12-22 23:48:56
(6 months ago)
2025-12-22 22:53:17 /+CSCOE+/logon.html
2025-12-22 22:53:18 /+webvpn+/index.html,{"body":"Login=Logi ...
show more
2025-12-22 22:53:17 /+CSCOE+/logon.html
2025-12-22 22:53:18 /+webvpn+/index.html,{"body":"Login=Login\u0026csrf_token=ce55da37030c28002704f113f92745f8e85a2a4f\u0026group_list=\u0026next=\u0026password=jlayden\u0026tgcookieset=\u0026tgroup=\u0026username=jlayden","content_type":"application/x-www-form-urlencoded","header":{"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8"],"Accept-Encoding":["deflate, gzip"],"Accept-Language":["en-US,en;q=0.9"],"Cache-Control":["max-age=0"],"Connection":["keep-alive"],"Content-Length":["136"],"Content-Type":["application/x-www-form-urlencoded"],"Cookie":["webvpnlogin=1; webvpnLang=en"],"Upgrade-Insecure-Requests":["1"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64)"]},"host":"161.189.135.131","method":"POST","proto":"HTTP/1.1","remote_addr":"216.26.254.193:21377","status_code":200,"url":"/+webvpn+/index.html","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64)"}
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:22:44
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.193 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:22:38.822182 2025] [security2:error] [pid 2815:tid 2815] [client 216.26.254.193:44793] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cajunpicasso.com"] [uri "/.git/HEAD"] [unique_id "aSa4zsdw9_KrdoSSZgI54wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:07:06
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.193 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:06:59.416101 2025] [security2:error] [pid 5903:tid 5903] [client 216.26.254.193:54345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.johnberk.com"] [uri "/.env"] [unique_id "aSa1I7vLQn4fWmg5o8RCMQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 07:06:35
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.193 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 02:06:28.545241 2025] [security2:error] [pid 3697898:tid 3697906] [client 216.26.254.193:46033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eafm.org"] [uri "/.git/HEAD"] [unique_id "aSam9BXsw-P_EAMOaarlbwAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack