๐ซ๐ฎ
JimArchon72
2026-08-03 11:50:03
(2 weeks ago)
2026/08/03 11:45:23 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
๐บ๐ธ
cwytech
2026-05-23 01:21:31
(2 months ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 21:46:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 17:46:49.328791 2026] [security2:error] [pid 10216:tid 10216] [client 89.19.34.210:62273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coolcustomproducts.com"] [uri "/wp-config.php~"] [unique_id "ag4ryc-YfzEdIA_ahTQPHQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 17:59:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 13:58:55.869661 2026] [security2:error] [pid 32092:tid 32092] [client 89.19.34.210:19679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cienmalos.com"] [uri "/wp-config.php.orig"] [unique_id "ag32XxC6GE2d1t9zuOif0wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 16:21:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:21:36.646995 2026] [security2:error] [pid 20887:tid 20887] [client 89.19.34.210:45911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soundtrax.net"] [uri "/wp-config.php.dist"] [unique_id "ag3fkLN0ZMgpI9kh-kWJpgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 12:57:26
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:57:22.867634 2026] [security2:error] [pid 3039:tid 3039] [client 89.19.34.210:55203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianwhitty.com"] [uri "/.wp-config.php.swp"] [unique_id "ag2vsow0cuKAtePjLSRVIAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-05-16 11:48:08
(3 months ago)
(mod_security) mod_security (id:20000010) triggered by 89.19.34.210 (US/United States/-): 5 in the l ...
show more
(mod_security) mod_security (id:20000010) triggered by 89.19.34.210 (US/United States/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-17 11:44:41
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 07:44:36.265818 2026] [security2:error] [pid 3852630:tid 3852630] [client 89.19.34.210:28609] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||celltechs.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "celltechs.net"] [uri "/"] [unique_id "aeIdJOqzKvVn07DrPx9FdAAAAA8"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2026-03-25 14:40:11
(4 months ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-18 01:49:41
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 20:49:33.603128 2026] [security2:error] [pid 11842:tid 11842] [client 89.19.34.210:13223] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.ezsmiledental.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.ezsmiledental.com"] [uri "/"] [unique_id "aZUardyVYHcIF375TOlvAgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-13 04:46:48
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 89.19.34.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 23:46:42.714071 2025] [security2:error] [pid 4614:tid 4614] [client 89.19.34.210:32995] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.domainexecs.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.domainexecs.com"] [uri "/"] [unique_id "aTzvsvv9t0iYaSaerTd34gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
wil.com
2024-09-25 09:00:41
(1 year ago)
GlobalProtect login attempts with user vblack.
VPN IP
Brute-Force
๐ท๐บ
sms.ru
2024-09-23 07:40:10
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
Anonymous
2023-11-24 05:00:18
(2 years ago)
Malicious activity detected
Hacking
Web App Attack
๐ช๐ธ
Cognisant-Security
2023-05-01 20:23:40
(3 years ago)
Attempts to login using invalid Admin level credentials
Hacking
Web App Attack