🇪🇸
librebit
2026-09-11 04:25:28
(3 hours ago)
Brute force
Brute-Force
🇫🇷
Sklurk
2026-08-17 01:39:13
(3 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-06-20 02:10:06
(2 months ago)
Web App Attack
Web App Attack
🇦🇺
2000cn.com.au
2026-05-10 12:57:46
(4 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-02-19 21:06:24
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 16:06:17.914291 2026] [security2:error] [pid 31613:tid 31613] [client 104.207.46.238:21941] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newerc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newerc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZd7SXhP-Vb-pdv-6nVuYgAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2025-12-24 04:50:30
(8 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
🇫🇷
solution.it
2025-12-10 16:55:45
(9 months ago)
[Wed Dec 10 17:55:44.233478 2025] [php7:error] [pid 3133967:tid 3133967] [client 104.207.46.238:5978 ...
show more
[Wed Dec 10 17:55:44.233478 2025] [php7:error] [pid 3133967:tid 3133967] [client 104.207.46.238:59789] script '/var/www/html/blog.solution.it/wp-login.php' not found or unable to stat
show less
Web App Attack
🇦🇺
MAGIC
2025-12-07 00:05:36
(9 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇮🇩
Kencang.ID
2025-12-06 10:31:49
(9 months ago)
Failed Login Attempt 2025-12-06 10:31:49 | 104.207.46.238 | Desktop | Safari | Ashburn, Virginia, Un ...
show more
Failed Login Attempt 2025-12-06 10:31:49 | 104.207.46.238 | Desktop | Safari | Ashburn, Virginia, United States | 3xK Tech GmbH | Mozilla/5.0 (Macintosh; Intel Mac OS X 13_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15
show less
FTP Brute-Force
Brute-Force
🇺🇸
TPI-Abuse
2025-11-25 04:40:39
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:40:32.727766 2025] [security2:error] [pid 32310:tid 32310] [client 104.207.46.238:45053] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thepinman.org"] [uri "/.env"] [unique_id "aSUzQCKnUyIqXcZxGYhl_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 04:07:37
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:07:30.098679 2025] [security2:error] [pid 13764:tid 13764] [client 104.207.46.238:14983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kylight.net"] [uri "/.env"] [unique_id "aSUrgojrtEsy1PaRoxeifgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 03:41:19
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:41:10.713123 2025] [security2:error] [pid 3573:tid 3573] [client 104.207.46.238:21971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.telesto.pe"] [uri "/.git/HEAD"] [unique_id "aSUlVjhO6CDAnoogwAkxBAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 03:21:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:20:57.115408 2025] [security2:error] [pid 24316:tid 24316] [client 104.207.46.238:35735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.silalaw.com"] [uri "/.env"] [unique_id "aSUgmU5cLKTfzahyHDOAUAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 02:49:12
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:49:02.190133 2025] [security2:error] [pid 13207:tid 13207] [client 104.207.46.238:41095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.avrknives.com"] [uri "/.svn/wc.db"] [unique_id "aSUZHq0By9ULSkn3ZjLjzQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 02:08:12
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.46.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:08:05.709037 2025] [security2:error] [pid 882:tid 882] [client 104.207.46.238:17631] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||skipspsaexchange.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "skipspsaexchange.com"] [uri "/2020.db"] [unique_id "aSUPhTtMNmlfGMx3rhGzqQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack