๐ซ๐ท
Baking333
2026-06-06 15:53:51
(1 day ago)
[redacted] 104.207.37.119 - - [06/Jun/2026:16:53:49 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 3 ...
show more
[redacted] 104.207.37.119 - - [06/Jun/2026:16:53:49 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 302 5273 0/57560 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" [redacted] 104.207.37.119 - - [06/Jun/2026:16:53:50 +0100] "GET //[redacted]?rsd HTTP/1.1" 302 1544 0/52062 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2026-05-08 02:34:07
(4 weeks ago)
(From [email protected] ) Hi,
Quick noteโฆ
Just rolled out a 100% free giveaway, and I saved you ...
show more
(From [email protected] ) Hi,
Quick noteโฆ
Just rolled out a 100% free giveaway, and I saved you a spot.
Jump in here before it closes:
https://suniljaindvg.systeme.io/6850adaf
A winner will be pickedโฆ might as well be you, right?
If you donโt want to receive any more messages from me, please complete the form on my website
show less
Phishing
Web Spam
๐ฑ๐ป
garmtech.com
2026-05-03 04:17:24
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 07-17.104.207.37.119.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 07-17.104.207.37.119.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-30 14:26:45
(1 month ago)
Attempted access to sensitive endpoint (/.env.local) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.env.local) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐ฉ๐ช
LRob.fr
2026-04-24 19:15:02
(1 month ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
4server
2026-04-21 07:17:01
(1 month ago)
[TueApr2109:16:57.8248242026][security2:error][pid3025238:tid3025266][client104.207.37.119:0]ModSecu ...
show more
[TueApr2109:16:57.8248242026][security2:error][pid3025238:tid3025266][client104.207.37.119:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"grigorov.ch\"][uri\"/db.sql\"][unique_id\"aeckaZrE_IcxiUza34QVcgAAABI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 08:08:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 03:08:07.331338 2026] [security2:error] [pid 2915:tid 2921] [client 104.207.37.119:45527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howardhallis.com"] [uri "/.git/objects/54/e2fb2f5fbb483b6d396fae843568c41f110dee"] [unique_id "aak552bdh7c6FWT9QFVMCwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-08 18:01:06
(5 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:01:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:01:37.156932 2025] [security2:error] [pid 25873:tid 25873] [client 104.207.37.119:48057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.californiastarsfarm.com"] [uri "/.env"] [unique_id "aSQe8d4YeOHL763wpYBs6QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:30:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:29:53.484446 2025] [security2:error] [pid 27207:tid 27207] [client 104.207.37.119:28809] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.osbyink.com"] [uri "/.svn/wc.db"] [unique_id "aSP7YdZrCxeqs6TojWzeLgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:38:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:38:26.202512 2025] [security2:error] [pid 24073:tid 24073] [client 104.207.37.119:49449] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rmjaero.com"] [uri "/.git/HEAD"] [unique_id "aSPvUquc85NktoO6dVOsuwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:33:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:32:58.773435 2025] [security2:error] [pid 32570:tid 32570] [client 104.207.37.119:16691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.travel-pix.com"] [uri "/.env"] [unique_id "aSPf-nDnkZeFeRmRg2HwbgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:12:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:12:03.559699 2025] [security2:error] [pid 4630:tid 4639] [client 104.207.37.119:54333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.retrieversocal.com"] [uri "/.git/HEAD"] [unique_id "aSPbE6cxawx_aukreZu0zwAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 03:34:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:34:07.576932 2025] [security2:error] [pid 563:tid 563] [client 104.207.37.119:34125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mosherpit.com"] [uri "/.git/HEAD"] [unique_id "aSPSL_XvjvaJcpXYw9DLhAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-29 14:34:42
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack