๐ฆ๐บ
afleventoffice.com.au
2026-09-24 05:06:24
(1 day ago)
GET /wp-sitemap.xml HTTP/1.1
Web App Attack
๐จ๐ฟ
lp
2026-09-18 10:49:42
(1 week ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 104.207.42.39
2026-09-18T11:54:36+02: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 104.207.42.39
2026-09-18T11:54:36+02:00 vpn Access-Reject 'beatriz' station: 104.207.42.39 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-18T11:55:58+02:00 vpn Access-Reject 'nico' station: 104.207.42.39 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ฉ๐ช
paissangroup
2026-09-12 04:35:48
(1 week ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
backslash
2026-09-08 19:21:04
(2 weeks ago)
block ruleset 51D5331ECDCF70C2C6410C0D0EEB5F69B17B5F56
Bad Web Bot
๐ฉ๐ช
NxtGenIT
2026-09-03 18:49:24
(3 weeks ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html?fcadbadd=1 HTTP/1.1" 200 -,
Brute-Force
๐ฉ๐ช
Goetz
2026-09-03 09:28:29
(3 weeks ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2026-06-18 07:58:30
(3 months ago)
Web attack blocked by Wordfence on mergel.nu (1 hit). Reported by CRMON.
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 16:05:55
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 11:05:49.779049 2026] [security2:error] [pid 14400:tid 14400] [client 104.207.42.39:29369] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oxfordgrpco.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oxfordgrpco.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZiGXWEZ04OAAS5Gl3ernwAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 09:36:41
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 04:36:36.753648 2026] [security2:error] [pid 32696:tid 32696] [client 104.207.42.39:50727] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cobbwebb.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cobbwebb.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZgrJADvD-fzLQEgQYtKrQAAACQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 16:05:25
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 11:05:17.038556 2026] [security2:error] [pid 7783:tid 7783] [client 104.207.42.39:16267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apwstl.com"] [uri "/.env"] [unique_id "aYyovT16Ob55aev-uqBnfgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-11 04:53:20
(7 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /site/.git/config (Rule ID: 930130) - Restricted File Access Attempt
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 00:17:19
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 19:17:12.991491 2026] [security2:error] [pid 31460:tid 31460] [client 104.207.42.39:31177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apropa.org"] [uri "/frontend/.env"] [unique_id "aYvKiDy24exHz07mA4C2qAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 22:59:35
(7 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-10 04:02:56
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:02:49.343707 2026] [security2:error] [pid 479:tid 479] [client 104.207.42.39:29029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icbsmonitor.net"] [uri "/api/.git/config"] [unique_id "aYqt6dHDPr-SwiDtxlLGLwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack