π―π΅
VXG-NET
2026-06-10 18:43:35
(1 week ago)
port=80, indicator_type=info-leak
Hacking
π«π·
Jean Valjean
2026-01-04 17:47:31
(5 months ago)
Fail2ban Caboom : xmlrpc.php Abuse
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-29 05:57:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:57:42.991046 2025] [security2:error] [pid 9897:tid 9897] [client 104.207.38.119:54445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maycockfamily.com"] [uri "/.git/HEAD"] [unique_id "aVIYVt8BL2HkT69_AEzS4AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-01 20:29:15
(6 months ago)
botnet
DDoS Attack
πΊπΈ
TPI-Abuse
2025-11-26 11:11:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:10:59.230337 2025] [security2:error] [pid 1835:tid 1835] [client 104.207.38.119:49541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.southfloridachoppers.com"] [uri "/.env"] [unique_id "aSbgQ-rXRiS7lZxfWvkAwgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 05:26:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:26:35.053802 2025] [security2:error] [pid 1938:tid 1938] [client 104.207.38.119:13879] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.trispeccorp.com"] [uri "/.env"] [unique_id "aSaPi8cd3vM78izIoTvfTgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 01:30:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:30:27.703836 2025] [security2:error] [pid 13027:tid 13027] [client 104.207.38.119:12811] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.biff0.com"] [uri "/.env"] [unique_id "aSZYM80mhOllCetiNPZMvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 00:09:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:09:28.790127 2025] [security2:error] [pid 9142:tid 9161] [client 104.207.38.119:59163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clearwaterpumpservices.com"] [uri "/.svn/wc.db"] [unique_id "aSZFOFT3DtRs3FbC9tniFAAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 07:19:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:19:45.448356 2025] [security2:error] [pid 16171:tid 16171] [client 104.207.38.119:44193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pseudospace.com"] [uri "/.svn/wc.db"] [unique_id "aSVYkeEinrvVJEc5rqu82gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 06:31:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:31:27.985347 2025] [security2:error] [pid 14307:tid 14307] [client 104.207.38.119:32083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.natursac.com"] [uri "/.env"] [unique_id "aSVNP5BMHxU0StQOVKLO0AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 03:16:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:16:35.451677 2025] [security2:error] [pid 1647140:tid 1647199] [client 104.207.38.119:9247] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supernumerarios.wizart.org"] [uri "/.svn/wc.db"] [unique_id "aSUfk8WdNO_bFaD03ZY2IwAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 01:42:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:42:20.113962 2025] [security2:error] [pid 23317:tid 23317] [client 104.207.38.119:28397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conveyorizedovens.com"] [uri "/.svn/wc.db"] [unique_id "aSUJfFM6MhWZV7_5L1vDWwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 10:38:14
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-08 06:39:08
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 01:39:01.168704 2025] [security2:error] [pid 24150:tid 24150] [client 104.207.38.119:14627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cucciniello.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aQ7lhSmJvr3qE17IYorODgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-17 14:44:26
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack