๐จ๐ญ
4server
2026-05-26 13:55:51
(1 week ago)
[TueMay2615:55:46.2991342026][security2:error][pid2122246:tid2122454][client104.207.32.140:0]ModSecu ...
show more
[TueMay2615:55:46.2991342026][security2:error][pid2122246:tid2122454][client104.207.32.140:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"edilmarra.ch\"][uri\"/wp-config.php.save\"][unique_id\"ahWmYvEflQV0xdzzbv9PCwAAAMI\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob.fr
2026-05-25 05:15:10
(1 week ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
Anonymous
2025-12-04 03:24:26
(6 months ago)
2025-12-04T05:24:24.807131+02:00 zanati wp(www.sahpa.co.za)[382619]: Blocked authentication attempt ...
show more
2025-12-04T05:24:24.807131+02:00 zanati wp(www.sahpa.co.za)[382619]: Blocked authentication attempt for [email protected] from 104.207.32.140
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:09:11
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:09:03.689265 2025] [security2:error] [pid 10516:tid 10516] [client 104.207.32.140:48461] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||skipspsaexchange.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "skipspsaexchange.com"] [uri "/a.db"] [unique_id "aSUPv3Ir4DgydFHeSH32HQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-24 11:00:59
(6 months ago)
[24/Nov/2025:22:00:58 +1100] "GET /.git/HEAD HTTP/1.1" 301 250 "Mozilla/5.0 (Windows NT 10.0; Win64; ...
show more
[24/Nov/2025:22:00:58 +1100] "GET /.git/HEAD HTTP/1.1" 301 250 "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:41:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:41:18.942732 2025] [security2:error] [pid 7708:tid 7708] [client 104.207.32.140:22049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gpaarch.com"] [uri "/.git/HEAD"] [unique_id "aSQoPvM0MBdd6lhmmoeRVAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
NotACaptcha
2025-11-24 07:27:07
(6 months ago)
webserver:80 [24/Nov/2025] "GET /.aws/credentials HTTP/1.1" 302 446 "-" "Mozilla/5.0 (Windows NT 10 ...
show more
webserver:80 [24/Nov/2025] "GET /.aws/credentials HTTP/1.1" 302 446 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:38:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:37:56.420282 2025] [security2:error] [pid 13415:tid 13415] [client 104.207.32.140:57053] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jessicabaer.com"] [uri "/.svn/wc.db"] [unique_id "aSPvNEHB_1r7nvqKHI4HrAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:19:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:19:02.588936 2025] [security2:error] [pid 24821:tid 24821] [client 104.207.32.140:51799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ronaldagrant.com"] [uri "/.git/HEAD"] [unique_id "aSPctnfyhohIzWYze3wsHgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 10:53:20
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.32.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 05:53:17.755052 2025] [security2:error] [pid 18795:tid 18795] [client 104.207.32.140:18859] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cephedanisman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cephedanisman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRmtHTuG547QNWCFdvVxTAAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 09:09:48
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-10-29 10:21:04
(7 months ago)
WP Admin Scan Activities
Web App Attack
Anonymous
2025-10-15 21:32:22
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ง๐ท
hostseries
2025-10-13 17:07:17
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-10-11 03:20:22
(7 months ago)
Attempted brute force login to web vpn 72 time(s); last attempt for 2025.10.11 is noted in report ti ...
show more
Attempted brute force login to web vpn 72 time(s); last attempt for 2025.10.11 is noted in report timestamp
show less
Hacking
Brute-Force