๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
nowyouknow
2025-12-30 15:38:27
(5 months ago)
(From [email protected] ) Hello,
My name is Charlotte Douglas, and I re ...
show more
(From [email protected] ) Hello,
My name is Charlotte Douglas, and I represent Coastal Electric Services. We are currently evaluating potential partners for an upcoming opportunity and would like to confirm the following:
โข Your availability to support new projects in Q1 2026
โข Your interest in receiving additional project details
Once we have confirmed both availability and interest, we will provide the project scope and further information.
Thank you for your time. We look forward to hearing from you.
Best regards,
Charlotte Douglas
Project Executive
show less
Phishing
Web Spam
Anonymous
2025-12-22 16:10:52
(5 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:54:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:54:17.141675 2025] [security2:error] [pid 32473:tid 32473] [client 104.207.44.31:20285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thehappywillow.com"] [uri "/.env"] [unique_id "aSU2eU7cIFTzlCsDhsiz7AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:02:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:01:52.612931 2025] [security2:error] [pid 9889:tid 9889] [client 104.207.44.31:27993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michaelpanesar.com"] [uri "/.env"] [unique_id "aSUcICJ0YyY_qOE3gdQIIQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:36:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:36:08.610540 2025] [security2:error] [pid 15101:tid 15113] [client 104.207.44.31:23463] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.icbc-canada.com"] [uri "/.git/HEAD"] [unique_id "aSUICKNKS2jdjfTVKRc7tAAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:24:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:23:53.611171 2025] [security2:error] [pid 26745:tid 26745] [client 104.207.44.31:18729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aquatreat.net"] [uri "/.git/HEAD"] [unique_id "aST3GfRFoYdlIKHhdu67DAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:06:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:06:18.652835 2025] [security2:error] [pid 1590769:tid 1590792] [client 104.207.44.31:17535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eifm.eu.aafm.us"] [uri "/.git/HEAD"] [unique_id "aSTy-mGwGZE4_DDLbJbMKAAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:39:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:39:15.166183 2025] [security2:error] [pid 18934:tid 18934] [client 104.207.44.31:16597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.altoshp.com"] [uri "/.env"] [unique_id "aSQnw15yDE7NMm9CdY7aLQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:12:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:12:40.205713 2025] [security2:error] [pid 10128:tid 10128] [client 104.207.44.31:27165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lincolnsoftwareinc.com"] [uri "/.svn/wc.db"] [unique_id "aSPpSGNEPwsHp2SXJzjTXwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:47:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:47:13.564855 2025] [security2:error] [pid 13779:tid 13779] [client 104.207.44.31:27089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.debbieweibler.com"] [uri "/.svn/wc.db"] [unique_id "aSPjUdegxZr0x-s-Md1qqQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:14:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:14:23.341144 2025] [security2:error] [pid 7332:tid 7332] [client 104.207.44.31:38727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.holdingfamily.com"] [uri "/.svn/wc.db"] [unique_id "aSPbn_KtrsCjFzYml3bFpgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 03:48:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:47:53.640677 2025] [security2:error] [pid 18192:tid 18241] [client 104.207.44.31:52399] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "30acre.net"] [uri "/.env"] [unique_id "aSPVaSagYJ-Jn6Tmn4suMAAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 01:15:09
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-29 10:03:27
(7 months ago)
GlobalProtect login attempts with user aaltshuler.
VPN IP
Brute-Force