🇺🇦
URAN Publishing Service
2026-09-14 11:59:49
(1 day ago)
[14/Sep/2026:14:59:48 +0300] -- 104.207.41.217 Ban reason: Scanner [CMS_GENERIC] | Request: GET /xml ...
show more
[14/Sep/2026:14:59:48 +0300] -- 104.207.41.217 Ban reason: Scanner [CMS_GENERIC] | Request: GET /xmlrpc.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇬🇧
rakkor
2026-09-11 03:00:44
(4 days ago)
2026-09-11T04:00:43+01:00 NAS [Fri Sep 11 04:00:43.052558 2026] [proxy_fcgi:error] [pid 3550:tid 355 ...
show more
2026-09-11T04:00:43+01:00 NAS [Fri Sep 11 04:00:43.052558 2026] [proxy_fcgi:error] [pid 3550:tid 3554] [client 104.207.41.217:59032] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Hacking
🇱🇻
garmtech.com
2026-09-10 12:41:55
(5 days ago)
Attempted access to sensitive endpoint (/wp-login.php) detected. Automated scan or unauthorized prob ...
show more
Attempted access to sensitive endpoint (/wp-login.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇨🇿
Countryman
2026-09-05 00:10:02
(1 week ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇩🇪
NxtGenIT
2026-09-03 17:40:37
(1 week ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html?fcadbadd=1 HTTP/1.1" 200 -,
Brute-Force
🇺🇸
mnsf
2026-02-19 23:05:19
(6 months ago)
Scanning/Probing (22)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 23:14:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 18:14:32.080133 2026] [security2:error] [pid 9389:tid 9389] [client 104.207.41.217:49299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verdeprofundo.net"] [uri "/v2/.git/config"] [unique_id "aZZH2Dl8T-pixgFiuzV2egAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-02-18 22:06:04
(6 months ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-02-18 20:18:04
(6 months ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 20:05:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 15:05:05.521752 2026] [security2:error] [pid 25935:tid 25935] [client 104.207.41.217:11547] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tractiondrive.com"] [uri "/.env.save"] [unique_id "aZYbcTZqBy77ug1eHbzHOgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 18:47:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:47:11.269083 2026] [security2:error] [pid 32589:tid 32589] [client 104.207.41.217:51261] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thommesen.net"] [uri "/test/.git/config"] [unique_id "aZYJL6fDVyu0TcDJaDi91gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 12:36:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:36:31.917424 2026] [security2:error] [pid 18344:tid 18344] [client 104.207.41.217:18861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wedemandavote.com"] [uri "/v2/.git/config"] [unique_id "aZWyTzRwC1KLWs-H7dTB-AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 11:48:16
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:48:13.228414 2026] [security2:error] [pid 1147:tid 1147] [client 104.207.41.217:60093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wanderlust-fineartphotos.com"] [uri "/frontend/.env"] [unique_id "aZWm_fk-z73lyS-4c76NmQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-22 17:48:15
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 04:36:48
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:36:45.811359 2025] [security2:error] [pid 23669:tid 23669] [client 104.207.41.217:41915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amyisms.com"] [uri "/.git/HEAD"] [unique_id "aSUyXW8Fu4Ivz8_u9bcnBwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack