๐จ๐ฆ
dispensight
2026-06-20 15:37:23
(1 week ago)
ngrok traffic to secureleaf-fraud-api-v1.ngrok.io: 1 req(s) [GET]. URIs: /wp-json/gravitysmtp/v1/tes ...
show more
ngrok traffic to secureleaf-fraud-api-v1.ngrok.io: 1 req(s) [GET]. URIs: /wp-json/gravitysmtp/v1/tesโฆ. UA: curl/8.7.1. ISP: 3xK Tech GmbH. Flag: known exploit/credential probe path.
show less
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-07 13:37:19
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-37.104.207.39.166.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-37.104.207.39.166.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
oncord
2026-05-07 07:47:54
(1 month ago)
Form spam
Web Spam
๐จ๐ญ
backslash
2026-05-05 20:06:00
(1 month ago)
block ruleset 6A1105329D233F6F53B9B61CE056BD4DAAE75AB4
Web Spam
๐ซ๐ท
masterguru
2026-04-06 10:43:17
(2 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 104.207.39.166 (US/United States/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 104.207.39.166 (US/United States/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ฆ๐บ
MAGIC
2026-04-06 01:26:37
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
DrLex0
2026-03-26 08:08:12
(3 months ago)
Crawler impersonating GoogleBot, fetching URLs prohibited by robots.txt
104.207.39.166 443 - [26/Ma ...
show more
Crawler impersonating GoogleBot, fetching URLs prohibited by robots.txt
104.207.39.166 443 - [26/Mar/2026:08:08:12 +0000] "GET [redacted] HTTP/1.1" 200 16141 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-22 03:30:21
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.39.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.39.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 22:30:17.484850 2026] [security2:error] [pid 17120:tid 17120] [client 104.207.39.166:59253] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||digitalracemedia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "digitalracemedia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZp4SYYsKnvI_xv6f5poyAAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 15:46:27
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.39.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.39.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 10:46:20.952487 2026] [security2:error] [pid 23039:tid 23039] [client 104.207.39.166:44053] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||joeordie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "joeordie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZiBzLkCCQR0DV0KjNgtRwAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 12:26:21
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.39.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.39.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 07:26:15.679600 2026] [security2:error] [pid 10721:tid 10721] [client 104.207.39.166:23457] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||redlandssprinkler.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "redlandssprinkler.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZhS54ahBp4qKTXqy45I2wAAACE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-01-16 16:44:58
(5 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -57.593 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -57.593 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
Anonymous
2025-12-11 16:31:46
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 20:02:11
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 15:02:04.938592 2025] [security2:error] [pid 468:tid 468] [client 104.207.39.166:12413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.luckypupdesigns.com"] [uri "/.env"] [unique_id "aSNoPDJBmoNoS_JrL7rN5QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 13:42:13
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-29 07:20:04
(7 months ago)
GlobalProtect login attempts with user drstever.
VPN IP
Brute-Force