π¦πΊ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
πΊπΈ
TPI-Abuse
2026-02-26 13:51:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 08:51:44.770673 2026] [security2:error] [pid 26162:tid 26162] [client 104.207.43.207:56551] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.145"] [uri "/.git/config"] [unique_id "aaBP8BxkuFU-9uHQuZgz7QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2026-02-03 00:30:24
(4 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
dtorrer
2026-01-21 17:43:46
(4 months ago)
General vulnerability scan.
Port Scan
πΊπΈ
TPI-Abuse
2026-01-21 11:52:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 06:52:35.474939 2026] [security2:error] [pid 3701615:tid 3701615] [client 104.207.43.207:45579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "demondomain.com"] [uri "/.svn/wc.db"] [unique_id "aXC-AwA7y8dtxpVK818_0AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-01-20 21:47:58
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
πΊπΈ
fbarela
2025-12-29 04:00:20
(5 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-12-14 23:20:17
(5 months ago)
botnet
DDoS Attack
πΊπΈ
TPI-Abuse
2025-11-24 06:56:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:55:50.092609 2025] [security2:error] [pid 23773:tid 23773] [client 104.207.43.207:32585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.paihianz.com"] [uri "/.svn/wc.db"] [unique_id "aSQBdt--ENSrrGTHkvNjfwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:38:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:38:01.096395 2025] [security2:error] [pid 18325:tid 18347] [client 104.207.43.207:20301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.credit-card-cap.com"] [uri "/.git/HEAD"] [unique_id "aSPhKbibCkDUtlE56PAiJgAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:08:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:08:16.824366 2025] [security2:error] [pid 3965136:tid 3965158] [client 104.207.43.207:49899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.movetodc.com"] [uri "/.git/HEAD"] [unique_id "aSPaMDGAQlEvBxWyTv-4bQAAAZQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 03:36:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:36:41.857723 2025] [security2:error] [pid 24557:tid 24557] [client 104.207.43.207:28741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bzbdesigns.com"] [uri "/.svn/wc.db"] [unique_id "aSPSyRtsTXj9PznqffPDGgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-07 08:48:33
(6 months ago)
[redacted] 104.207.43.207 - - [07/Nov/2025:09:48:20 +0100] "POST /xmlrpc.php HTTP/2.0" 200 448 "-" " ...
show more
[redacted] 104.207.43.207 - - [07/Nov/2025:09:48:20 +0100] "POST /xmlrpc.php HTTP/2.0" 200 448 "-" "Mozilla/5.0 (iPad; CPU OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1"
[redacted] 104.207.43.207 - - [07/Nov/2025:09:48:21 +0100] "POST /xmlrpc.php HTTP/2.0" 200 448 "-" "Ruby, Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:30.0) Gecko/20100101 Firefox/30.0"
[redacted] 104.207.43.207 - - [07/Nov/2025:09:48:23 +0100] "POST /xmlrpc.php HTTP/2.0" 200 448 "-" "Mozilla/5.0 (iPad; CPU OS 8_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12D508 Safari/600.1.4"
[redacted] 104.207.43.207 - - [07/Nov/2025:09:48:24 +0100] "POST /xmlrpc.php HTTP/2.0" 200 448 "-" "Mozilla/5.0 (Linux; Android 6.0; vivo 1713 Build/MRA58K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.124 Mobile Safari/537.36"
[redacted] 104.207.43.207 - - [07/Nov/2025:09:48:25 +0100] "POST /xmlrpc.php HTTP
...
show less
Hacking
Web App Attack
Anonymous
2025-10-29 08:56:12
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
π¨π¦
wil.com
2025-10-17 15:18:45
(7 months ago)
GlobalProtect login attempts with user bfrancis.
VPN IP
Brute-Force