πͺπΈ
librebit
2026-06-25 14:58:50
(3 days ago)
Brute force
Brute-Force
πΊπΈ
mnsf
2026-06-01 14:06:16
(3 weeks ago)
Scanning/Probing (34)
Brute-Force
Web App Attack
π©πͺ
todix
2026-05-27 22:30:33
(1 month ago)
Web App Attack Exploid from 104.207.46.131
Web App Attack
π¨π
backslash
2026-02-18 22:40:04
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-02-18 20:08:57
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 15:08:50.125790 2026] [security2:error] [pid 9832:tid 9832] [client 104.207.46.131:55365] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharonmauldin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharonmauldin.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZYcUjtgVc0j7sDArehf_QAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
F242
2026-01-30 05:19:11
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-02 08:49:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 03:49:06.864430 2025] [security2:error] [pid 14191:tid 14191] [client 104.207.46.131:11103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "explorediablo.com"] [uri "/.env"] [unique_id "aS6oAle0xph8J1atgO6ZtwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-02 06:54:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 01:54:53.470564 2025] [security2:error] [pid 7524:tid 7524] [client 104.207.46.131:27695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manaplas.com"] [uri "/.env"] [unique_id "aS6NPevLOtSCTwj33jZFcAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-02 05:18:01
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:17:55.212049 2025] [security2:error] [pid 5102:tid 5102] [client 104.207.46.131:44307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spores101.com"] [uri "/.env"] [unique_id "aS52g85UY-9E6_9j5djcOwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Packets-Decreaser.NET
2025-11-30 13:09:59
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-11-25 06:32:33
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:32:30.264740 2025] [security2:error] [pid 32007:tid 32007] [client 104.207.46.131:25543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.andiamorun.com"] [uri "/.svn/wc.db"] [unique_id "aSVNfiYi3JvRhXIDZVfwKQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 06:14:02
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:13:52.292701 2025] [security2:error] [pid 14226:tid 14332] [client 104.207.46.131:40865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.psds.link.omegaoak.com"] [uri "/.svn/wc.db"] [unique_id "aSVJIJF6HRvJfyrmJlm6QAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-25 03:50:33
(7 months ago)
Malicious activity detected
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 02:26:44
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:26:36.552142 2025] [security2:error] [pid 13795:tid 13795] [client 104.207.46.131:27633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.pbeyer.org"] [uri "/.svn/wc.db"] [unique_id "aSUT3MpJk_nXff8i_TofVQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 21:44:26
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack