๐ฑ๐ป
garmtech.com
2026-03-09 04:42:44
(2 months ago)
IM360 WAF: Attempt to upload malware
Hacking
๐ฑ๐ป
garmtech.com
2026-03-09 04:42:36
(2 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
๐ฆ๐บ
rubixstudios
2026-03-04 04:18:34
(3 months ago)
(mod_security) mod_security (id:1004100) triggered by 104.207.35.244 (US/United States/-): 5 in the ...
show more
(mod_security) mod_security (id:1004100) triggered by 104.207.35.244 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Hacking
Web App Attack
๐ฉ๐ช
F242
2026-01-30 05:14:13
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:02:00
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-12-22 18:28:37
(5 months ago)
Attempted brute force login to web vpn 126 time(s); last attempt for 2025.12.22 is noted in report t ...
show more
Attempted brute force login to web vpn 126 time(s); last attempt for 2025.12.22 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-02 20:08:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 15:07:57.969348 2025] [security2:error] [pid 6417:tid 6417] [client 104.207.35.244:42547] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gmsdigita.com"] [uri "/.env"] [unique_id "aS9HHXpn6pwMqD9duXicdQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-02 16:16:03
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 10:05:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 05:05:31.227875 2025] [security2:error] [pid 424358:tid 424470] [client 104.207.35.244:13735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fastesttrademark.com"] [uri "/.git/HEAD"] [unique_id "aS656_p__Pmf5kEIOQBptgAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:50:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:50:35.111347 2025] [security2:error] [pid 30966:tid 30966] [client 104.207.35.244:25793] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mystudioinparis.com"] [uri "/.svn/wc.db"] [unique_id "aS5-K41g9tbfaMct_MMt5gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:18:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:18:51.607649 2025] [security2:error] [pid 2989:tid 2989] [client 104.207.35.244:58743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stephanjonker.com"] [uri "/.git/HEAD"] [unique_id "aS52u3WODej9kEw8jx7DhgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 04:53:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:53:28.061758 2025] [security2:error] [pid 11112:tid 11112] [client 104.207.35.244:17039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biomechanicalwars.com"] [uri "/.svn/wc.db"] [unique_id "aS5wyJS2sNInFTs6V9QIBQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 04:32:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:32:31.155905 2025] [security2:error] [pid 12599:tid 12599] [client 104.207.35.244:17305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rivercityacct.com"] [uri "/.svn/wc.db"] [unique_id "aS5r3xTyfd9HXyQ685pDnQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-11-19 06:57:45
(6 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-11-13 21:42:40
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack