๐ฉ๐ช
FeG Deutschland
2026-06-23 00:47:14
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฉ๐ช
fleckenbase
2026-06-09 16:04:17
(2 weeks ago)
apache-noscript
...
Brute-Force
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-05-22 11:43:21
(1 month ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
๐จ๐ณ
ThreatBook.io
2026-05-12 22:34:13
(1 month ago)
ThreatBook Intelligence: http_proxy,Zombie more details on https://threatbook.io/ip/104.207.41.137
2 ...
show more
ThreatBook Intelligence: http_proxy,Zombie more details on https://threatbook.io/ip/104.207.41.137
2026-05-12 18:13:26 /v3/api-docs
2026-05-12 18:13:25 /swagger/docs/v1
2026-05-12 18:13:25 /api/swagger.json
2026-05-12 18:13:24 /swagger/v1/swagger.json
2026-05-12 18:13:23 /v2/api-docs
2026-05-12 18:13:23 /prod-api/v2/api-docs
show less
Web App Attack
Anonymous
2026-04-10 08:07:30
(2 months ago)
Forum/form spam
Web Spam
๐ฆ๐บ
MAGIC
2026-04-09 02:27:18
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐จ๐ณ
ThreatBook.io
2026-04-04 22:33:14
(2 months ago)
ThreatBook Intelligence: http_proxy,Zombie more details on https://threatbook.io/ip/104.207.41.137
2 ...
show more
ThreatBook Intelligence: http_proxy,Zombie more details on https://threatbook.io/ip/104.207.41.137
2026-04-04 16:19:21 /nacos/%23/serviceSync
show less
Web App Attack
๐บ๐ธ
mind5t0rm
2026-03-28 00:08:25
(2 months ago)
(XMLRPC) WP XMLPRC Attack 104.207.41.137 (US/United States/-): 3 in the last 3600 secs; Ports: *; Di ...
show more
(XMLRPC) WP XMLPRC Attack 104.207.41.137 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 104.207.41.137 - - [28/Mar/2026:07:08:21 +0700] "GET /xmlrpc.php HTTP/1.1" 403 165 "https://publicworkscomplianceadvisors.com" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
104.207.41.137 - - [28/Mar/2026:07:08:23 +0700] "GET /xmlrpc.php HTTP/1.1" 403 165 "https://publicworkscomplianceadvisors.com" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
104.207.41.137 - - [28/Mar/2026:07:08:24 +0700] "GET /xmlrpc.php HTTP/1.1" 403 165 "https://publicworkscomplianceadvisors.com" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
show less
Port Scan
Anonymous
2026-03-05 19:57:51
(3 months ago)
Forum/form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-02-23 09:36:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 04:36:34.084212 2026] [security2:error] [pid 8500:tid 8500] [client 104.207.41.137:36825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "connec-tek.com.simia.com"] [uri "/.git/config"] [unique_id "aZwfoocsyAoNPo5s_q-F6gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:58:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:58:37.953111 2026] [security2:error] [pid 17588:tid 17588] [client 104.207.41.137:62401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ken-parker.com"] [uri "/api/.git/config"] [unique_id "aZZ8XWgLngN2ENsN1YrDjwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:28:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:28:41.301162 2026] [security2:error] [pid 6358:tid 6358] [client 104.207.41.137:22749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kbalan.com"] [uri "/backup/.git/config"] [unique_id "aZZ1WfJte1E_9DcYFHpYvwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-02-19 01:39:01
(4 months ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
mnsf
2026-02-18 22:05:12
(4 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 21:23:56
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 16:23:50.534272 2026] [security2:error] [pid 19708:tid 19708] [client 104.207.41.137:42319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tyning.com"] [uri "/admin/.env"] [unique_id "aZYt5gfpd8OFosgfQRfhYQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack