π±π»
garmtech.com
2026-03-29 14:26:17
(2 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
π«π·
masterguru
2026-03-27 22:21:22
(2 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 104.207.42.202 (US/United States/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 104.207.42.202 (US/United States/-): 1 in the last 3600 secs (0-193)
show less
Hacking
π±π»
garmtech.com
2026-03-15 01:16:52
(2 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
π¨π
backslash
2026-02-23 21:48:00
(3 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
π©πͺ
paissangroup
2026-01-03 13:51:51
(5 months ago)
Multiple WAF Violations
Web App Attack
π§π·
Sipo ChutΓ£o
2025-12-31 03:00:01
(5 months ago)
/.svn/wc.db
Hacking
Anonymous
2025-12-28 20:12:02
(5 months ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
Anonymous
2025-12-08 12:45:21
(6 months ago)
botnet
DDoS Attack
πΊπΈ
TPI-Abuse
2025-11-26 11:58:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:58:48.827188 2025] [security2:error] [pid 26772:tid 26836] [client 104.207.42.202:34255] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arthansl.com"] [uri "/.env"] [unique_id "aSbreHmAvLO2HMScmBCcJgAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 08:55:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:55:42.393957 2025] [security2:error] [pid 19984:tid 19984] [client 104.207.42.202:60007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.alexthepunk.com"] [uri "/.env"] [unique_id "aSbAjpJDhRanXSZtRLg7lgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 02:07:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:07:24.453274 2025] [security2:error] [pid 15558:tid 15558] [client 104.207.42.202:34763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.saintlouiscentral.com"] [uri "/.env"] [unique_id "aSZg3D3PqfeNcztPLPX-SwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 00:39:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:39:48.158886 2025] [security2:error] [pid 17466:tid 17479] [client 104.207.42.202:52815] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kincers.com"] [uri "/.git/HEAD"] [unique_id "aSZMVJvX96wK2APxLO0WoQAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 09:00:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:00:35.694467 2025] [security2:error] [pid 3740550:tid 3740550] [client 104.207.42.202:39351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.christineaholtz.com"] [uri "/.svn/wc.db"] [unique_id "aSQeszS8blatIUBQl01iSQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:58:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:58:17.936168 2025] [security2:error] [pid 18865:tid 18865] [client 104.207.42.202:50891] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.terazon.net"] [uri "/.env"] [unique_id "aSPl6bRP3SLCMuElyxhq0AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-18 01:42:40
(7 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force