๐ฑ๐ป
garmtech.com
2026-05-18 20:01:52
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-01.104.207.39.1.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-01.104.207.39.1.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 08:07:55
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 03:07:49.474428 2026] [security2:error] [pid 5953:tid 6031] [client 104.207.39.1:11865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howardhallis.com"] [uri "/.git/objects/f4/c7d8da3df46d1520e6df107a26a445be618f61"] [unique_id "aak51e9_LUubsM0EwzyNAgAAAcc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-24 17:24:17
(6 months ago)
botnet
DDoS Attack
Anonymous
2025-12-22 14:27:45
(6 months ago)
Attempted brute force login to web vpn 126 time(s); last attempt for 2025.12.22 is noted in report t ...
show more
Attempted brute force login to web vpn 126 time(s); last attempt for 2025.12.22 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-26 01:30:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:29:56.213335 2025] [security2:error] [pid 13324:tid 13324] [client 104.207.39.1:31799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.biff0.com"] [uri "/.git/HEAD"] [unique_id "aSZYFN0vsYxKHufaegz6igAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:57:20
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:57:05.630290 2025] [security2:error] [pid 6227:tid 6227] [client 104.207.39.1:29405] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kathiekate.com"] [uri "/.env"] [unique_id "aSUpEUPxRjyKuHedT3XszQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:09:45
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:09:39.929921 2025] [security2:error] [pid 2411:tid 2411] [client 104.207.39.1:57955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.miraclepunchy.com"] [uri "/.svn/wc.db"] [unique_id "aSTzw5uZfZuJS_9VC4UoogAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:32:18
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:32:11.345833 2025] [security2:error] [pid 23017:tid 23017] [client 104.207.39.1:15929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gabosoftware.com"] [uri "/.env"] [unique_id "aSQmG4hLaTwAbF-8kjcHawAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:57:31
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:57:23.636128 2025] [security2:error] [pid 1644:tid 1644] [client 104.207.39.1:15751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.redlinechemical.com"] [uri "/.env"] [unique_id "aSQd81TvCKk2JtLvklU23AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:40:24
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:40:20.121345 2025] [security2:error] [pid 14452:tid 14452] [client 104.207.39.1:19755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bzbdesigns.com"] [uri "/.git/HEAD"] [unique_id "aSQZ9DRo2AvaUd8U7yCGGgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:34:03
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:33:55.853258 2025] [security2:error] [pid 23755:tid 23755] [client 104.207.39.1:22703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nysasports.com"] [uri "/.env"] [unique_id "aSP8U4DsyOGZxOU_ER5Q8gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:06:19
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:06:12.595487 2025] [security2:error] [pid 4043:tid 4043] [client 104.207.39.1:13773] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cbtattam.com"] [uri "/.git/HEAD"] [unique_id "aSPnxHpA0nsWn96zhVH5EAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 21:04:59
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
RLDD
2025-11-02 02:51:28
(7 months ago)
WP probing -nov
Web App Attack
Anonymous
2025-10-18 08:36:28
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force