๐ฑ๐ป
garmtech.com
2026-07-30 06:51:15
(1 month ago)
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:0
Hacking
๐จ๐ณ
ThreatBook.io
2026-04-01 23:48:22
(4 months ago)
ThreatBook Intelligence: vpn_proxy,Gateway more details on https://threatbook.io/ip/104.207.35.2
202 ...
show more
ThreatBook Intelligence: vpn_proxy,Gateway more details on https://threatbook.io/ip/104.207.35.2
2026-04-01 18:08:09 /
show less
Web App Attack
๐ฆ๐บ
MAGIC
2026-03-08 01:51:57
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-22 13:35:56
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 08:35:53.995676 2026] [security2:error] [pid 1579:tid 1579] [client 104.207.35.2:59327] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kratka.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kratka.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZsGOX8Gg_gBiY4WCbXaHwAAABo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-21 17:32:52
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 12:32:48.404833 2026] [security2:error] [pid 18008:tid 18008] [client 104.207.35.2:27677] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rjdyckarchitect.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rjdyckarchitect.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZnsQMLQq9VapnTIRih-DwAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-21 13:36:49
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 08:36:41.700029 2026] [security2:error] [pid 27607:tid 27607] [client 104.207.35.2:44453] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bordwell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bordwell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZm06a-fwqsMgGXsJuHk2gAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-28 05:31:07
(7 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐จ๐ณ
ThreatBook.io
2026-01-04 23:26:33
(7 months ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/104.207.35.2
2026-01-0 ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/104.207.35.2
2026-01-04 14:23:25 /.env
2026-01-04 21:31:29 /video/index.php?c=search&catid=23%20and%20(select%201%20from%20(select%20count(*),concat(md5(1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)
2026-01-04 12:56:50 /
2026-01-04 12:56:50 /?redirect:${%23req%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23s%3dnew%20java.util.Scanner((new%20java.lang.ProcessBuilder(%27netstat%20-an%27.toString().split(%27\\s%27))).start().getInputStream()).useDelimiter(%27\\AAAA%27),%23str%3d%23s.hasNext()?%23s.next():%27%27,%23resp%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23resp.setCharacterEncoding(%27UTF-8%27),%23resp.getWriter().println(%23str),%23resp.getWriter().flush(),%23resp.getWriter().close()}
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-12-23 23:50:34
(8 months ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/104.207.35.2
2025-12-2 ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/104.207.35.2
2025-12-23 17:17:53 /shop/index.php?c=search&catid=23%20and%20(select%201%20from%20(select%20count(*),concat(md5(1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)
2025-12-23 20:14:43 /fang/index.php?c=search&catid=23%20and%20(select%201%20from%20(select%20count(*),concat(md5(1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)
2025-12-23 22:44:19 /druid/index.html
show less
Web App Attack
Anonymous
2025-12-14 15:00:14
(8 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:55:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:55:18.755840 2025] [security2:error] [pid 7392:tid 7392] [client 104.207.35.2:57801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.title15.com"] [uri "/.svn/wc.db"] [unique_id "aSQPZg1hngS2V807nOs_yQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:57:35
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:57:31.296629 2025] [security2:error] [pid 524:tid 524] [client 104.207.35.2:57197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heathdiesel.com"] [uri "/.svn/wc.db"] [unique_id "aSPzy3TSVN3s9NKnfUtPIgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:33:35
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:33:31.003397 2025] [security2:error] [pid 3354155:tid 3354155] [client 104.207.35.2:39855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srtgloballogistics.srtmanagementservices.com"] [uri "/.git/HEAD"] [unique_id "aSPuK_VHRiBfytf6RisUoQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 12:14:38
(9 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฉ๐ช
tinect
2025-10-19 16:18:39
(10 months ago)
authentication failure
Brute-Force
SSH