๐ซ๐ท
Sklurk
2026-07-07 16:26:54
(1 month ago)
Web App Attack
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-05-13 09:42:31
(3 months ago)
Honeypot detection: FTP brute-force or anonymous access attempt on port 21. Severity: MEDIUM. Aaran. ...
show more
Honeypot detection: FTP brute-force or anonymous access attempt on port 21. Severity: MEDIUM. Aaran.cloud
show less
FTP Brute-Force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-13 13:52:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 08:52:01.863690 2026] [security2:error] [pid 2991315:tid 2991315] [client 104.207.35.0:53415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "minetterisquez.com"] [uri "/api/.env"] [unique_id "aY8sgdIXCz6bh6r_XXjIlQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-02-13 08:55:22
(6 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-13 04:48:35
(6 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.git/config (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .git/ found within REQUEST_FILENAME: /.git/config]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 04:20:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 23:20:15.706408 2026] [security2:error] [pid 20930:tid 20930] [client 104.207.35.0:38089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "martaaizenman.com"] [uri "/v2/.git/config"] [unique_id "aY6mf5wR-PUMmqWfSp8UQQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 03:31:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 22:31:51.519029 2026] [security2:error] [pid 1240640:tid 1240640] [client 104.207.35.0:31299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mariannehansen.com"] [uri "/.env.save"] [unique_id "aY6bJ4jwGAiD_a7CHQIYsgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 02:47:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 21:47:21.399991 2026] [security2:error] [pid 4567:tid 4567] [client 104.207.35.0:32345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manichri.com"] [uri "/.env.save"] [unique_id "aY6QuRy29Dzznquq8m8hvQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 00:56:13
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 19:56:08.643684 2026] [security2:error] [pid 2569:tid 2569] [client 104.207.35.0:58707] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madandproud.com"] [uri "/api/.git/config"] [unique_id "aY52qG-raLCIolj6PW_-IAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 17:34:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 12:34:03.967914 2026] [security2:error] [pid 1179541:tid 1179567] [client 104.207.35.0:34227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dermatologycolorado.com"] [uri "/.env"] [unique_id "aY4PCwvMeIDAwpaY0ftsfwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 16:00:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 11:00:37.315427 2026] [security2:error] [pid 18511:tid 18511] [client 104.207.35.0:47927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dictionaryoffish.com"] [uri "/.git/config"] [unique_id "aY35JZ0R5VJ714gJvz8ARAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
eacontent
2026-01-18 14:04:00
(7 months ago)
104.207.35.0 - - [13/Jan/2026:02:33:52 -0500] "GET /.env HTTP/1.1" 404 34 "-" "Mozilla/5.0 (Windows ...
show more
104.207.35.0 - - [13/Jan/2026:02:33:52 -0500] "GET /.env HTTP/1.1" 404 34 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 12:35:10
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 07:35:05.606734 2026] [security2:error] [pid 5425:tid 5425] [client 104.207.35.0:51385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenewplantation.org"] [uri "/.svn/wc.db"] [unique_id "aWY7-eAJKwhVdaTQbFWdVAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 10:36:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 05:36:16.518590 2025] [security2:error] [pid 7006:tid 7006] [client 104.207.35.0:35487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifeinsmoke.com"] [uri "/.git/HEAD"] [unique_id "aVJZoDIiQRcVle3CxR-ajgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 06:43:12
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:43:04.902432 2025] [security2:error] [pid 23925:tid 23925] [client 104.207.35.0:57603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewillsmith.com"] [uri "/.env"] [unique_id "aVIi-Jp3LvAAp7NqbDbq8QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack