๐ฌ๐ง
PeravixGroup
2026-05-06 19:09:51
(4 weeks ago)
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity ...
show more
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity: CRITICAL. Aaran.cloud
show less
Hacking
Exploited Host
๐ฌ๐ง
PeravixGroup
2026-05-06 08:52:13
(4 weeks ago)
Honeypot detection: FTP brute-force or anonymous access attempt on port 21. Severity: MEDIUM. Aaran. ...
show more
Honeypot detection: FTP brute-force or anonymous access attempt on port 21. Severity: MEDIUM. Aaran.cloud
show less
FTP Brute-Force
Brute-Force
Anonymous
2026-04-12 05:53:55
(1 month ago)
Attempt to scan vulnerabilities
Hacking
๐จ๐ญ
backslash
2026-01-24 19:10:03
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-07 13:56:48
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 08:56:42.125047 2025] [security2:error] [pid 25372:tid 25372] [client 104.207.44.69:22213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lemoulinavent.org"] [uri "/.svn/wc.db"] [unique_id "aTWHmvop1BwKqlBV8L2S8wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 13:07:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 08:07:19.932906 2025] [security2:error] [pid 21983:tid 21983] [client 104.207.44.69:45267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exhaustthelimits.org"] [uri "/.git/HEAD"] [unique_id "aTV8B0oVfK2V1Nqc_uXfTgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 12:34:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 07:33:58.400134 2025] [security2:error] [pid 22562:tid 22586] [client 104.207.44.69:34147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "careofsouls.org"] [uri "/.svn/wc.db"] [unique_id "aTV0Nv3H797K7ujZtSfqGwAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 10:55:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 05:55:18.007176 2025] [security2:error] [pid 1560:tid 1560] [client 104.207.44.69:24447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diegogamazo.com"] [uri "/.svn/wc.db"] [unique_id "aTK6FldElcNtEZViVmcIJwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:28:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:28:08.249590 2025] [security2:error] [pid 24741:tid 24741] [client 104.207.44.69:42679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mrbss.com"] [uri "/.svn/wc.db"] [unique_id "aSU-aIGWcmovZqa_kn9jsQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:49:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:49:04.306465 2025] [security2:error] [pid 6695:tid 6705] [client 104.207.44.69:12535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flu.xavidominguez.com"] [uri "/.env"] [unique_id "aSU1QPecScAqKSdZtGzGvgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:51:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:51:41.215750 2025] [security2:error] [pid 26673:tid 26673] [client 104.207.44.69:15605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rwfrancis.com"] [uri "/.svn/wc.db"] [unique_id "aSUnzZL5gCN7M-3xj2LinwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:35:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:35:30.195375 2025] [security2:error] [pid 31452:tid 31452] [client 104.207.44.69:19027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ashotofcoffee.com"] [uri "/.git/HEAD"] [unique_id "aSUV8iLvsNfkMZ5Y5MqGFgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:57:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:57:10.307125 2025] [security2:error] [pid 643:tid 643] [client 104.207.44.69:57505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.johnhansonmemorial.org"] [uri "/.env"] [unique_id "aST-5iXBQxbbMdl_SbZhzwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:33:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:23:01.882267 2025] [security2:error] [pid 10435:tid 10435] [client 104.207.44.69:25027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.inexpensivecommerce.com"] [uri "/.git/HEAD"] [unique_id "aST25SL4x7dIt_atU8cYSQAAAH4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 01:26:25
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack