๐จ๐ญ
backslash
2026-05-23 05:12:18
(1 week ago)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-18 03:34:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 22:34:29.499229 2026] [security2:error] [pid 8194:tid 8194] [client 104.207.35.221:60453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rjdyckarchitect.com"] [uri "/api/.env"] [unique_id "aZUzRdBYjmuqnpxD6isgpwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 02:29:08
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 21:29:04.641476 2026] [security2:error] [pid 4632:tid 4632] [client 104.207.35.221:37391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "renperfco.com"] [uri "/.env"] [unique_id "aZUj8Mqy11x7v9nyedI7wQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(3 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2025-12-27 13:45:08
(5 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐ฎ๐น
VHosting
2025-12-24 05:05:25
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ซ๐ท
ingroscart.it
2025-11-24 10:04:37
(6 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.207.35.221 (US/United States/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-11-24 09:44:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:43:56.437126 2025] [security2:error] [pid 11880:tid 11880] [client 104.207.35.221:39669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.arellasoc.com"] [uri "/.svn/wc.db"] [unique_id "aSQo3CZyNjG5vyJlOMYgZgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:42:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:42:29.858741 2025] [security2:error] [pid 8980:tid 8980] [client 104.207.35.221:60103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.joshi.us"] [uri "/.env"] [unique_id "aSPwRYQEz-Li-cfsqHG8vAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-17 11:19:03
(6 months ago)
| Multiple SQL injection attempts from same source ip.(multiple servers)
Hacking
SQL Injection
Web App Attack
Anonymous
2025-11-14 02:10:53
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-16 23:36:12
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-16 17:45:22
(7 months ago)
GlobalProtect login attempts with user auk.
VPN IP
Brute-Force
Anonymous
2025-10-08 10:54:57
(7 months ago)
Attempted brute force login to web vpn 28 time(s); last attempt for 2025.10.08 is noted in report ti ...
show more
Attempted brute force login to web vpn 28 time(s); last attempt for 2025.10.08 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-05 21:22:28
(8 months ago)
Attempted brute force login to web vpn 27 time(s); last attempt for 2025.10.05 is noted in report ti ...
show more
Attempted brute force login to web vpn 27 time(s); last attempt for 2025.10.05 is noted in report timestamp
show less
Hacking
Brute-Force