๐ซ๐ท
Sklurk
2026-06-20 00:26:00
(4 days ago)
Web App Attack
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-05-23 08:39:25
(1 month ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ฑ๐ป
garmtech.com
2026-04-14 07:49:52
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-49.104.207.33.122.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-49.104.207.33.122.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ช๐ธ
librebit
2026-03-28 02:45:34
(2 months ago)
Brute force
Brute-Force
Anonymous
2026-02-13 16:31:07
(4 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-02-13 13:19:57
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 08:19:50.995287 2026] [security2:error] [pid 27789:tid 27789] [client 104.207.33.122:18711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawyerholidaycards.com"] [uri "/.env.local"] [unique_id "aY8k9jVr5yqZNe1z5rfwwwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 08:00:19
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 03:00:14.931482 2026] [security2:error] [pid 24529:tid 24529] [client 104.207.33.122:54325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "melton.space"] [uri "/api/.env"] [unique_id "aY7aDrLmmEeZxhVyOjpdkgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 03:16:26
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 22:16:23.635820 2026] [security2:error] [pid 31815:tid 31815] [client 104.207.33.122:59135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marcedinc.com"] [uri "/new/.git/config"] [unique_id "aY6Xh6zt4DJJSkArsM2tAwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 20:06:54
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 15:06:46.871513 2026] [security2:error] [pid 7050:tid 7050] [client 104.207.33.122:40051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iconbizpromo.com"] [uri "/.git/config"] [unique_id "aY4y1qmd1hoi_UpjugnqUAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 17:08:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 12:08:32.125975 2026] [security2:error] [pid 14651:tid 14651] [client 104.207.33.122:57541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cwidisplays.com"] [uri "/.env"] [unique_id "aY4JEGCZzsEtH7JOPsLXRwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 16:46:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 11:46:35.178400 2026] [security2:error] [pid 22321:tid 22321] [client 104.207.33.122:58849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conveyorizedovens.com"] [uri "/.env"] [unique_id "aY4D65vd05cS1ndGrZYhawAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 09:34:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 04:34:07.793195 2026] [security2:error] [pid 14481:tid 14481] [client 104.207.33.122:40867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdpeters.com"] [uri "/app/.git/config"] [unique_id "aY2ej_rDAe1LzGNf9FErrwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 07:29:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 02:29:12.557248 2026] [security2:error] [pid 19974:tid 19974] [client 104.207.33.122:50529] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arzoma.com"] [uri "/new/.git/config"] [unique_id "aY2BSBIH3edPmmqILh2eWwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 20:18:54
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 15:18:50.127765 2026] [security2:error] [pid 12331:tid 12331] [client 104.207.33.122:29125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archmediaptyltd.com"] [uri "/app/.env"] [unique_id "aYzkKuDwtvgZxHsyi1irpQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 13:46:20
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.33.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 08:46:17.358001 2026] [security2:error] [pid 373:tid 373] [client 104.207.33.122:30745] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||erinrusso.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "erinrusso.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYyIKUxY3anEStA6p8YBDwAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack