๐ฑ๐ป
garmtech.com
2026-03-13 11:34:26
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-34.104.207.45.249.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-34.104.207.45.249.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฆ๐บ
oncord
2026-03-12 20:48:45
(2 months ago)
Form spam
Web Spam
๐ฆ๐บ
MAGIC
2026-02-23 00:45:52
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ช๐ธ
10dencehispahard SL
2026-01-26 07:34:10
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-01-11 06:51:48
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.45.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.45.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 11 01:51:38.311842 2026] [security2:error] [pid 21431:tid 21431] [client 104.207.45.249:14221] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||genesis-castle.com|F|2"] [data ".ini.ea3.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "genesis-castle.com"] [uri "/php.ini.ea3.bak"] [unique_id "aWNIerNpcswNduwg_F3v5wAAAAY"], referer: http://genesis-castle.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-23 16:25:21
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ณ๐ฑ
homeshowdomain.nl
2025-11-25 22:59:12
(6 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2025-11-24.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
nowyouknow
2025-11-25 03:01:20
(6 months ago)
Phishing
Web Spam
Anonymous
2025-11-24 10:20:02
(6 months ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:37:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:37:15.570103 2025] [security2:error] [pid 10479:tid 10479] [client 104.207.45.249:29735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dalebeyer.com"] [uri "/.git/HEAD"] [unique_id "aSQnS3Rt5K_h59hjhQdAzgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:39:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:39:09.353819 2025] [security2:error] [pid 21922:tid 21922] [client 104.207.45.249:17771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.johnatuttle.com"] [uri "/.git/HEAD"] [unique_id "aSQZrZeQ500EGTf3vIGyVwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:21:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:20:27.157078 2025] [security2:error] [pid 28306:tid 28306] [client 104.207.45.249:49991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.donutburger.com"] [uri "/.svn/wc.db"] [unique_id "aSQHO4CSpSwMs1GWEU9bhgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2025-11-21 13:11:58
(6 months ago)
Phishing
Web Spam
Anonymous
2025-11-13 21:30:48
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
nowyouknow
2025-11-12 12:12:11
(6 months ago)
Phishing
Web Spam