๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-01-02 20:07:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 15:06:42.544925 2026] [security2:error] [pid 23176:tid 23176] [client 104.207.32.94:24485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tanvie.joanofartdesign.com"] [uri "/.svn/wc.db"] [unique_id "aVglUloOHuXKxL60hsT1qwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-12-07 00:00:39
(6 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-12-02 13:42:08
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:49:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:49:04.874532 2025] [security2:error] [pid 5683:tid 5683] [client 104.207.32.94:42997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.scoutinsignia.com"] [uri "/.env"] [unique_id "aSU1QIvlZQ2Oyd6QpsLU4gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:10:35
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:10:28.601156 2025] [security2:error] [pid 29202:tid 29202] [client 104.207.32.94:42571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.emisoni.com"] [uri "/.git/HEAD"] [unique_id "aSUsNL1oe6bn3urI8icv4QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:57:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:56:57.426672 2025] [security2:error] [pid 18875:tid 18875] [client 104.207.32.94:9681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.salazartransfers.com"] [uri "/.git/HEAD"] [unique_id "aSUa-YAACtF-S85q1gtGKAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:10:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:10:12.282994 2025] [security2:error] [pid 1647139:tid 1647155] [client 104.207.32.94:57711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.certifiedjournalist.aafm.us"] [uri "/.svn/wc.db"] [unique_id "aSUB9J5eMzOQPKYL6rLzFwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:44:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:44:52.048750 2025] [security2:error] [pid 12048:tid 12048] [client 104.207.32.94:22793] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wooferhound.com"] [uri "/.env"] [unique_id "aST8BPljw9rE7rz2oZ0pFwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:20:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:20:42.281045 2025] [security2:error] [pid 17024:tid 17094] [client 104.207.32.94:47579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.layoverlocations.com"] [uri "/.git/HEAD"] [unique_id "aST2Wl6p-b22U1h8szr6NwAAAcU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 17:41:06
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2025-11-13 05:08:05
(6 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2025-10-18 09:55:57
(7 months ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force
๐จ๐ฆ
wil.com
2025-10-16 18:12:32
(7 months ago)
GlobalProtect login attempts with user grandis.
VPN IP
Brute-Force
Anonymous
2025-10-14 02:40:50
(7 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.14 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.14 is noted in report timestamp
show less
Hacking
Brute-Force