๐ซ๐ท
masterguru
2026-05-06 13:15:00
(1 month ago)
*Port Scan* detected from 104.207.42.17 (US/United States/-). 11 hits in the last 186 seconds (0-195 ...
show more
*Port Scan* detected from 104.207.42.17 (US/United States/-). 11 hits in the last 186 seconds (0-195)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-15 12:17:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 07:17:35.102216 2026] [security2:error] [pid 12099:tid 12099] [client 104.207.42.17:59941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.env"] [unique_id "aWja32kYBUNtfTrz1L-u5AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-15 08:39:49
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:42
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-29 05:27:12
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:27:08.163494 2025] [security2:error] [pid 12094:tid 12094] [client 104.207.42.17:52447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bridgenevercrossed.com"] [uri "/.git/HEAD"] [unique_id "aVIRLK7cB7E-RvJt933OUgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:53:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:53:14.662957 2025] [security2:error] [pid 659:tid 659] [client 104.207.42.17:52427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehealthcontent.com"] [uri "/.svn/wc.db"] [unique_id "aVIJOv166mHJ5lYXel60YAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:31:54
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:31:50.688777 2025] [security2:error] [pid 16813:tid 16813] [client 104.207.42.17:19193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jackieherbach.com"] [uri "/.svn/wc.db"] [unique_id "aVIENm11z8_N3YP7evIKEwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 03:39:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 22:39:50.585996 2025] [security2:error] [pid 22045:tid 22143] [client 104.207.42.17:48025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iamfluff.com"] [uri "/.git/HEAD"] [unique_id "aVH4BvqRylXFAPdQd1hbegAAAc0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-12-07 00:00:57
(6 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-12-06 11:42:52
(6 months ago)
botnet
DDoS Attack
Anonymous
2025-11-14 03:51:03
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ญ๐บ
bcsaba
2025-10-30 09:14:27
(7 months ago)
CMS (WordPress or Joomla) login attempt.
104.207.42.17 - - [30/Oct/2025:10:14:25 +0100] "POST /wp-lo ...
show more
CMS (WordPress or Joomla) login attempt.
104.207.42.17 - - [30/Oct/2025:10:14:25 +0100] "POST /wp-login.php HTTP/1.1" 200 11063 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0"
show less
Hacking
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-16 04:05:39
(7 months ago)
GlobalProtect login attempts with user zzy.
VPN IP
Brute-Force
Anonymous
2025-10-08 08:06:46
(7 months ago)
Attempted brute force login to web vpn 27 time(s); last attempt for 2025.10.08 is noted in report ti ...
show more
Attempted brute force login to web vpn 27 time(s); last attempt for 2025.10.08 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-06 18:36:01
(8 months ago)
Attempted brute force login to web vpn 54 time(s); last attempt for 2025.10.06 is noted in report ti ...
show more
Attempted brute force login to web vpn 54 time(s); last attempt for 2025.10.06 is noted in report timestamp
show less
Hacking
Brute-Force