๐ซ๐ท
Sklurk
2026-06-20 03:15:50
(6 days ago)
Web App Attack
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-17 23:20:01
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-20.104.207.32.235.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-20.104.207.32.235.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ณ๐ฟ
billyborsht
2026-05-15 23:03:39
(1 month ago)
2026-05-16T11:03:38.311017+12:00 southern wordpress(poetryinhell.org)[901640]: Authentication attemp ...
show more
2026-05-16T11:03:38.311017+12:00 southern wordpress(poetryinhell.org)[901640]: Authentication attempt for unknown user [email protected] from 104.207.32.235
...
show less
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-14 05:41:45
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-41.104.207.32.235.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-41.104.207.32.235.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ซ๐ท
dynamix
2026-04-22 18:14:20
(2 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 05:22:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 00:21:53.828635 2026] [security2:error] [pid 18144:tid 18144] [client 104.207.32.235:64085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kristencorley.com"] [uri "/.env.local"] [unique_id "aZad8QLmVtcUVCEaWEAU0gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-19 05:05:16
(4 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-02-19 00:12:58
(4 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 21:12:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 16:12:10.323575 2026] [security2:error] [pid 18511:tid 18511] [client 104.207.32.235:11651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "turtlehill.org"] [uri "/config/.env"] [unique_id "aZYrKqR07ZzIPYIxy2MrggAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 18:24:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:23:55.491502 2026] [security2:error] [pid 23777:tid 23777] [client 104.207.32.235:39045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thetheaterathollywoodandvine.com"] [uri "/api/.env"] [unique_id "aZYDuy8JqIpnuxe3l3TN0gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 13:19:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:19:14.127627 2026] [security2:error] [pid 1270704:tid 1270704] [client 104.207.32.235:38939] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "williamfitzsimmons.com"] [uri "/.env.local"] [unique_id "aZW8UiUWM-ayC9dpf-Fl2wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-02-18 12:38:41
(4 months ago)
(modsecurity) srv102 ModSecurity 104.207.32.235 (US/United States/-): 5 in the last 3600 secs; Ports ...
show more
(modsecurity) srv102 ModSecurity 104.207.32.235 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:52:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:52:42.489687 2026] [security2:error] [pid 804532:tid 804549] [client 104.207.32.235:18911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waqm.org"] [uri "/frontend/.env"] [unique_id "aZWoCiVMIGSGO_bGgZA4dwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-01-25 00:28:37
(5 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-28 01:14:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 20:14:21.227824 2025] [security2:error] [pid 7233:tid 7254] [client 104.207.32.235:23951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beckmon.com"] [uri "/.git/HEAD"] [unique_id "aVCEbXTAx2o--mB3fjkzTwAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack