๐ซ๐ท
Sklurk
2026-06-17 02:54:17
(1 week ago)
Web App Attack
Web App Attack
๐ฉ๐ช
Reinhard
2026-05-30 04:36:58
(4 weeks ago)
Parameter or path manipulation, hacking. /wordpress.sql
Hacking
๐ฉ๐ช
4server
2026-04-21 00:36:34
(2 months ago)
[TueApr2102:36:29.7678182026][security2:error][pid2446757:tid2446768][client104.207.39.103:0]ModSecu ...
show more
[TueApr2102:36:29.7678182026][security2:error][pid2446757:tid2446768][client104.207.39.103:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"chesasilva.ch\"][uri\"/chesasilva.sql\"][unique_id\"aebGjSM_zKWpNOzXIlv5GQAAAEg\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-03-11 22:44:25
(3 months ago)
Forum/form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-02-18 03:50:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 22:50:16.239806 2026] [security2:error] [pid 649:tid 649] [client 104.207.39.103:33319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robertseyewear.com"] [uri "/wp/.git/config"] [unique_id "aZU2-IT86zZn4P_C35BJpQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 00:50:45
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 19:50:41.713675 2026] [security2:error] [pid 1077:tid 1077] [client 104.207.39.103:27531] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulomiranda.eu"] [uri "/test/.git/config"] [unique_id "aZUM4U-ZF61k8WNeg3cTXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-01-30 06:01:15
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
fbarela
2026-01-25 04:01:00
(5 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-12-12 12:00:52
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:25:07
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:24:57.270907 2025] [security2:error] [pid 31402:tid 31402] [client 104.207.39.103:26065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.highaltitudebaking.com"] [uri "/.git/HEAD"] [unique_id "aSQWWWAFVROFTnINoYTe-AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:46:23
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:46:00.363503 2025] [security2:error] [pid 2876:tid 2876] [client 104.207.39.103:28945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fynebutts.postermodelsworldwideinc.com"] [uri "/.env"] [unique_id "aSQNOLI9RYi7v71RxZxx8AAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:36:10
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:36:05.998466 2025] [security2:error] [pid 22657:tid 22657] [client 104.207.39.103:60629] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mskimberleesspace.com"] [uri "/.env"] [unique_id "aSP81ZCbSNDuDcJIMK6yAwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:02:31
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:02:27.037926 2025] [security2:error] [pid 6436:tid 6436] [client 104.207.39.103:39613] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.neneh.biz"] [uri "/.git/HEAD"] [unique_id "aSPm46k5YHhCpfjvStoEggAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 04:50:30
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-18 07:24:14
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack