๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ซ๐ท
tilellit.pro
2026-02-22 09:52:42
(3 months ago)
Fail2Ban banned 104.207.44.72 for security violations in jail wp-armour. Log: 2026/02/22 09:52:41 [e ...
show more
Fail2Ban banned 104.207.44.72 for security violations in jail wp-armour. Log: 2026/02/22 09:52:41 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 104.207.44.72 | Target: wplogin" , client: 104.207.44.72, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฆ๐บ
MAGIC
2026-02-15 00:33:43
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ช๐ธ
10dencehispahard SL
2025-12-29 09:18:53
(5 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-12-22 18:57:33
(5 months ago)
Attempted brute force login to web vpn 126 time(s); last attempt for 2025.12.22 is noted in report t ...
show more
Attempted brute force login to web vpn 126 time(s); last attempt for 2025.12.22 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-26 01:41:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:41:45.949325 2025] [security2:error] [pid 22086:tid 22272] [client 104.207.44.72:33749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.super-8mm.net"] [uri "/.svn/wc.db"] [unique_id "aSZa2RCcVYSuHH558FyJQQAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:16:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:16:44.352804 2025] [security2:error] [pid 3365544:tid 3365636] [client 104.207.44.72:13259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.draas.info"] [uri "/.svn/wc.db"] [unique_id "aSZU_J6gyU3zOv0h7a5kHgAAAg4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:37:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:37:52.145377 2025] [security2:error] [pid 30728:tid 30728] [client 104.207.44.72:33139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grspipes.com"] [uri "/.env"] [unique_id "aSZL4JtcUF2iAxHbjFpc8QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:18:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:18:50.449324 2025] [security2:error] [pid 11796:tid 11796] [client 104.207.44.72:34735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thommesen.net"] [uri "/.git/HEAD"] [unique_id "aSU8Ot5W7UMEc4V-8-CNogAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:28:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:27:57.360845 2025] [security2:error] [pid 29647:tid 29647] [client 104.207.44.72:55107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bizzmail.net"] [uri "/.svn/wc.db"] [unique_id "aSUwTcuPnOGmtXZcP4RDGwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:53:01
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:52:53.908791 2025] [security2:error] [pid 8483:tid 8483] [client 104.207.44.72:13937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.asisecuresystems.com"] [uri "/.svn/wc.db"] [unique_id "aSQAxT_zd7coiXd58_fB2AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:46:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:46:20.579597 2025] [security2:error] [pid 521:tid 521] [client 104.207.44.72:36499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aifstudio.com"] [uri "/.git/HEAD"] [unique_id "aSPxLAtG4aJZyrmGoCNVMAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 19:26:06
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.44.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 14:25:59.541862 2025] [security2:error] [pid 12843:tid 12843] [client 104.207.44.72:57427] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.churchbehindthewalls.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.churchbehindthewalls.com"] [uri "/s3cmd.ini"] [unique_id "aRt2x5LnpcGKGlLDa5PVswAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antbr.com
2025-11-11 15:58:22
(6 months ago)
AntBR.com: [Repeated Attack]==> /.aws/credentials
Web App Attack
๐จ๐ฆ
wil.com
2025-10-14 10:49:58
(7 months ago)
GlobalProtect login attempts with user taklocko.
VPN IP
Brute-Force