Anonymous
2026-05-26 08:48:46
(3 weeks ago)
[server.tmg.gr] httpd-login-spray-site: sites=add2021.gr; logs=/var/log/httpd/domains/add2021.gr.log ...
show more
[server.tmg.gr] httpd-login-spray-site: sites=add2021.gr; logs=/var/log/httpd/domains/add2021.gr.log; samples=site_wide=true | distinct_ips=64 | /wp-login.php
show less
Hacking
Web App Attack
๐ฉ๐ช
iNetWorker
2026-05-25 22:42:55
(3 weeks ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 16:43:56
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 11:43:50.566549 2026] [security2:error] [pid 23677:tid 23677] [client 104.207.40.131:9907] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||banis-associates.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "banis-associates.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZiPRqc5toDVjN2rjCtcwQAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 06:04:13
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:04:07.223355 2025] [security2:error] [pid 21423:tid 21423] [client 104.207.40.131:46305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vittaria.com"] [uri "/.svn/wc.db"] [unique_id "aVIZ1xVJGed6Jd6HUsYG5gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:09:19
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:09:16.659417 2025] [security2:error] [pid 12751:tid 12751] [client 104.207.40.131:9647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathynash.com"] [uri "/.git/HEAD"] [unique_id "aVIM_EFyLZTBgvd825RLQAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-22 17:10:47
(5 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ง๐ช
madeit
2025-11-30 04:25:58
(6 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:13:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:13:44.227701 2025] [security2:error] [pid 956708:tid 956708] [client 104.207.40.131:22703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.theklines.net"] [uri "/.svn/wc.db"] [unique_id "aSVXKLLaWhJnQ8qU3XIZXgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:18:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:18:21.034530 2025] [security2:error] [pid 9067:tid 9067] [client 104.207.40.131:20583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psychoatomicpower.theknowledgemaster.com"] [uri "/.svn/wc.db"] [unique_id "aSQi3cATxf-kuzogLxbp8wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:22:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:22:24.900334 2025] [security2:error] [pid 28999:tid 29016] [client 104.207.40.131:47537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.idealcentralvac.com"] [uri "/.svn/wc.db"] [unique_id "aSP5oBHUG1yMWqoCx_DkpQAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:10:01
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:09:54.720870 2025] [security2:error] [pid 3424:tid 3424] [client 104.207.40.131:26015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rota.oxfordgliding.com"] [uri "/.svn/wc.db"] [unique_id "aSPoos90Do4D0E4jz9NtHAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 02:48:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.40.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 21:48:27.749533 2025] [security2:error] [pid 11777:tid 11777] [client 104.207.40.131:37083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gre-home.com"] [uri "/.svn/wc.db"] [unique_id "aSPHe6wNBXmlvjr0gLcS0gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 08:54:22
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ญ๐บ
zolav8
2025-11-10 01:16:39
(7 months ago)
SQL injection / web attack attempt
Hacking
SQL Injection
Anonymous
2025-10-18 02:21:31
(8 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force