π«π·
mail.avx.gr
2026-08-22 12:53:49
(22 hours ago)
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 216.26.254.226 - - [22/Aug/2026:15:53:48 +0300] "P ...
show more
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 216.26.254.226 - - [22/Aug/2026:15:53:48 +0300] "POST /wp-login.php HTTP/2.0" 403 1110 "https://candiatrade.gr/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15"
show less
Web App Attack
π²πΉ
Malta
2026-08-21 21:07:37
(1 day ago)
216.26.254.226 - - [21/Aug/2026:23:07:37 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; ...
show more
216.26.254.226 - - [21/Aug/2026:23:07:37 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15"
show less
Hacking
Web App Attack
πΊπΈ
lostswordfish.com
2026-08-21 19:00:06
(1 day ago)
Wordfence waf block on fairregistry
Web App Attack
πΊπ¦
Olexiy Backend
2026-08-05 01:29:05
(2 weeks ago)
216.26.254.226
...
Bad Web Bot
Web App Attack
π©πͺ
Blexyel
2026-07-16 20:35:46
(1 month ago)
216.26.254.226 - - [16/Jul/2026:22:35:45 +0200] "GET /wp-login.php HTTP/1.1" 200 2238 "-" "Mozilla/5 ...
show more
216.26.254.226 - - [16/Jul/2026:22:35:45 +0200] "GET /wp-login.php HTTP/1.1" 200 2238 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0" "git.fomx.gay"
...
show less
Brute-Force
Web App Attack
π©πͺ
LRob
2026-06-24 01:32:08
(1 month ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-05-13 04:26:56
(3 months ago)
[WedMay1306:26:54.6440872026][security2:error][pid1092721:tid1092794][client216.26.254.226:0]ModSecu ...
show more
[WedMay1306:26:54.6440872026][security2:error][pid1092721:tid1092794][client216.26.254.226:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"risanamento-pareti-umide.ch\"][uri\"/.aws/credentials\"][unique_id\"agP9jl5NInMi4fN3x5vi7gAAAIw\"]
show less
Port Scan
Brute-Force
Web App Attack
π©πͺ
bescared
2026-05-12 14:35:21
(3 months ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
π΅π±
dcnet
2026-03-08 00:00:00
(5 months ago)
SSL VPN brute force credential stuffing on FortiGate 100F - unknown user login attempts
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2025-11-24 09:27:21
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:27:15.285733 2025] [security2:error] [pid 17285:tid 17285] [client 216.26.254.226:49171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nctreillc.com"] [uri "/.svn/wc.db"] [unique_id "aSQk83Rwtj6LVa6NeoPnwgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 08:44:13
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:43:54.962930 2025] [security2:error] [pid 15588:tid 15588] [client 216.26.254.226:37559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.todi.org"] [uri "/.svn/wc.db"] [unique_id "aSQayl0ETFoznin-0LiIKAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 06:01:25
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:01:17.404493 2025] [security2:error] [pid 4133561:tid 4133567] [client 216.26.254.226:41745] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.guitarprimer.com"] [uri "/.env"] [unique_id "aSP0rc6lE8qghk7QOEVLXQAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 05:19:52
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:19:49.138449 2025] [security2:error] [pid 5103:tid 5152] [client 216.26.254.226:32723] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cityofmiddleton.org"] [uri "/.svn/wc.db"] [unique_id "aSPq9Vz8f4PiRLoPAIGsxgAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:52:56
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:52:47.667012 2025] [security2:error] [pid 23436:tid 23436] [client 216.26.254.226:21907] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fresh-cut.us"] [uri "/.git/HEAD"] [unique_id "aSPknx8O55kqtygVg34GQgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:36:09
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.254.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:36:03.141696 2025] [security2:error] [pid 12692:tid 12692] [client 216.26.254.226:34323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mike-garner.com"] [uri "/.svn/wc.db"] [unique_id "aSPgs9sS1gxABa5066ycpAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack