๐ฉ๐ช
LRob.fr
2026-06-12 02:30:56
(6 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
ph
2026-05-24 17:00:44
(3 weeks ago)
Bad web bot attempting to run wp-json on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 20:18:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 15:18:47.813324 2026] [security2:error] [pid 10909:tid 10909] [client 104.207.43.205:22751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archmediaptyltd.com"] [uri "/admin/.env"] [unique_id "aYzkJ2G7wQdu1I8Tty9E7wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฑ
ifiguero
2026-02-10 06:29:05
(4 months ago)
Web Attack (\x00\x00\x00\x00\x00). 7d ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 06:06:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 01:06:27.354276 2026] [security2:error] [pid 24564:tid 24564] [client 104.207.43.205:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail-pmg.com"] [uri "/api/.env"] [unique_id "aYrK42tCi8TaS5lt7SOeUQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-02-10 03:48:50
(4 months ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:23:26
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:23:20.758465 2026] [security2:error] [pid 2283755:tid 2283755] [client 104.207.43.205:28575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirbysmw.com"] [uri "/.env.staging"] [unique_id "aYqkqCvOPo-3fngt1wRusQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:43:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:43:37.865880 2026] [security2:error] [pid 18428:tid 18428] [client 104.207.43.205:53439] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kelticdreamsranch.com"] [uri "/site/.git/config"] [unique_id "aYpxKdCeI0iFjC6o1bwz8AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 23:37:33
(4 months ago)
Blocking for trying to access an exploit file: /.aws/credentials
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 23:08:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:08:03.685906 2026] [security2:error] [pid 15716:tid 15716] [client 104.207.43.205:51457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hpepaper.com"] [uri "/.env.save"] [unique_id "aYpo0_JVKUmQ01DCOEZLzwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:45:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:44:56.398404 2026] [security2:error] [pid 2318:tid 2318] [client 104.207.43.205:13595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houston-church-of-god.org"] [uri "/new/.git/config"] [unique_id "aYpjaJG9OfWRUzrr790zBwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-02-09 21:29:14
(4 months ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:20:07
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:19:59.661055 2026] [security2:error] [pid 7232:tid 7232] [client 104.207.43.205:57101] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kampinenlaw.com"] [uri "/api/.git/config"] [unique_id "aYpBb_ncX76mwSlK9O3gbwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-01-30 05:47:34
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2025-12-12 16:29:33
(6 months ago)
botnet
DDoS Attack