๐ซ๐ท
Sklurk
2026-06-23 03:47:29
(1 day ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-06-20 05:12:31
(4 days ago)
Web App Attack
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-24 06:08:12
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 09-08.104.207.38.92.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 09-08.104.207.38.92.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
Anonymous
2026-04-27 17:09:10
(1 month ago)
Forum/form spam
Web Spam
๐ฎ๐น
[email protected]
2026-04-17 22:29:15
(2 months ago)
[Sat Apr 18 00:29:15.093261 2026] [authz_core:error] [pid 560720:tid 560765] [remote 104.207.38.92:2 ...
show more
[Sat Apr 18 00:29:15.093261 2026] [authz_core:error] [pid 560720:tid 560765] [remote 104.207.38.92:21197] AH01630: client denied by server configuration: /var/www/html/MyWeb/Wordpress_www/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ฆ๐บ
MAGIC
2026-04-17 01:02:57
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-20 20:59:24
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 15:59:16.636443 2026] [security2:error] [pid 1680:tid 1680] [client 104.207.38.92:30767] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frootloops.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frootloops.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZjLJPCal4MGMdK9U5ETKQAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-02-20 01:34:17
(4 months ago)
*Port Scan* detected from 104.207.38.92 (US/United States/-).
Port Scan
๐บ๐ธ
TPI-Abuse
2026-02-09 21:48:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:48:36.677701 2026] [security2:error] [pid 12869:tid 12869] [client 104.207.38.92:12581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garyoneal.com"] [uri "/app/.git/config"] [unique_id "aYpWNPdjtjrTU4ZhwBrnCwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 18:37:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 13:37:45.244336 2026] [security2:error] [pid 8451:tid 8451] [client 104.207.38.92:38009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuzzyecho.com"] [uri "/api/.git/config"] [unique_id "aYopee6l75CHyeqqgIiYZgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 16:31:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 11:31:49.520141 2026] [security2:error] [pid 6283:tid 6283] [client 104.207.38.92:42583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftwwx.com"] [uri "/app/.env"] [unique_id "aYoL9aTCuDxn30GDFEdYPAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 03:16:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 22:16:11.795111 2026] [security2:error] [pid 4318:tid 4318] [client 104.207.38.92:64067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuegolounge813.com"] [uri "/.env.production"] [unique_id "aYlRe2acra2At0S3ileH-AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-02 09:58:38
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-27 18:57:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 13:57:08.751280 2025] [security2:error] [pid 31361:tid 31361] [client 104.207.38.92:13861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "a1laha.com"] [uri "/.env"] [unique_id "aSifBJwWhWG-2I8RnptMSQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 10:46:18
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack