π¦πΊ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2026-02-11 09:01:00
(4 months ago)
SMS pumping
DDoS Attack
VPN IP
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2026-01-13 00:10:25
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-01-11 12:36:49
(5 months ago)
botnet
DDoS Attack
π©πͺ
Packets-Decreaser.NET
2025-12-31 00:59:21
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-11-26 09:45:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 04:45:18.225820 2025] [security2:error] [pid 31559:tid 31559] [client 104.207.42.198:47567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dandksupply.com"] [uri "/.svn/wc.db"] [unique_id "aSbMLhNI1SZ6mUAj-Bn--gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 06:04:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:03:50.174817 2025] [security2:error] [pid 2650:tid 2658] [client 104.207.42.198:24271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thebiglies.us"] [uri "/.svn/wc.db"] [unique_id "aSaYRqcpXMNW-93ob63OVgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 05:37:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:37:51.595666 2025] [security2:error] [pid 1328:tid 1328] [client 104.207.42.198:41199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.westerncarolinabass.org"] [uri "/.svn/wc.db"] [unique_id "aSaSL59T9X8oI17fHYBJuwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 00:04:16
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:04:12.263602 2025] [security2:error] [pid 6944:tid 6944] [client 104.207.42.198:55573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.performingartsguild.com"] [uri "/.svn/wc.db"] [unique_id "aSZD_H3obybpu4NLIdUDfgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 06:24:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:23:57.157570 2025] [security2:error] [pid 26230:tid 26230] [client 104.207.42.198:19149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.yankeetownfishing.com"] [uri "/.env"] [unique_id "aSVLfRpyvDklhYourrkTGwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 05:28:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:28:41.332587 2025] [security2:error] [pid 29009:tid 29009] [client 104.207.42.198:50143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.intra.es"] [uri "/.svn/wc.db"] [unique_id "aSU-iddXazhk04t6eYyBMwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:25:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:25:09.234281 2025] [security2:error] [pid 31772:tid 31772] [client 104.207.42.198:14595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quizzersform.cmabiblequizzing.org"] [uri "/.env"] [unique_id "aSPeJWLblv8ojalhnj0USwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 14:20:27
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
π¨π¦
wil.com
2025-10-13 16:29:48
(8 months ago)
GlobalProtect login attempts with user schlagheckn.
VPN IP
Brute-Force
π¨π
backslash
2025-10-12 15:25:10
(8 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot