๐บ๐ธ
TPI-Abuse
2025-12-27 21:04:19
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 16:04:10.663572 2025] [security2:error] [pid 17303:tid 17303] [client 104.207.48.174:16685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lazymanvegan.com"] [uri "/.git/HEAD"] [unique_id "aVBJygbEPAjkq1ai7ZLiGwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-12-27 18:59:06
(5 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-27 17:51:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 12:51:36.250594 2025] [security2:error] [pid 14605:tid 14605] [client 104.207.48.174:18667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kbalan.com"] [uri "/.git/HEAD"] [unique_id "aVAcqChJdH8Jfk_WQl2MXgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
Mcshield.org
2025-12-01 04:29:11
(6 months ago)
UDP flood/amplification attempt srcport 11963 dstport 123 length 663
Fraud Orders
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-29 01:39:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 20:39:08.056402 2025] [security2:error] [pid 2744:tid 2759] [client 104.207.48.174:55881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "absurdotron.com"] [uri "/wp-config.php.old"] [unique_id "aSpOvJ96eI8INsfO89JRnwAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 19:19:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 14:19:37.125020 2025] [security2:error] [pid 1813681:tid 1813681] [client 104.207.48.174:25661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1214productions.com"] [uri "/.env.local"] [unique_id "aSn1yX_9_l12w1OEQOrjYQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 16:50:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 11:50:39.621394 2025] [security2:error] [pid 9549:tid 9549] [client 104.207.48.174:11215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestcountryclubs.com"] [uri "/.env.development"] [unique_id "aSnS35npssp_8xh-Kt4r9AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2025-11-04 14:31:34
(7 months ago)
Web App Attack
Anonymous
2025-11-01 22:13:41
(7 months ago)
[redacted] 104.207.48.174 - - [01/Nov/2025:23:13:16 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" " ...
show more
[redacted] 104.207.48.174 - - [01/Nov/2025:23:13:16 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8) Gecko/20051111 Firefox/1.5"
[redacted] 104.207.48.174 - - [01/Nov/2025:23:13:18 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Linux; Android 8.0.0; moto g(6) play Build/OPP27.91-87) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Mobile Safari/537.36"
[redacted] 104.207.48.174 - - [01/Nov/2025:23:13:21 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
[redacted] 104.207.48.174 - - [01/Nov/2025:23:13:22 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Linux; Android 7.1.1; SAMSUNG SM-J250M Build/NMF26X) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/7.4 Chrome/59.0.3071.125 Mobile Safari/537.36"
joerg-shimo
...
show less
Hacking
Web App Attack
Anonymous
2025-10-30 14:07:12
(7 months ago)
WordPress Brute Force
Brute-Force
๐ฉ๐ช
Marc
2025-10-29 19:54:39
(7 months ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2025-10-27 14:20:07
(7 months ago)
Unauthorized connection to SSH port 22
Port Scan
Hacking
SSH
๐จ๐ญ
altux
2025-10-27 09:03:40
(7 months ago)
Oct 27 10:03:36 altux6 sshd\[13014\]: Invalid user perkaholic100 from 104.207.48.174 port 52069
Oct ...
show more
Oct 27 10:03:36 altux6 sshd\[13014\]: Invalid user perkaholic100 from 104.207.48.174 port 52069
Oct 27 10:03:36 altux6 sshd\[13014\]: pam_unix\(sshd:auth\): authentication failure\; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.207.48.174
Oct 27 10:03:38 altux6 sshd\[13014\]: Failed password for invalid user perkaholic100 from 104.207.48.174 port 52069 ssh2
...
show less
Brute-Force
SSH
Anonymous
2025-10-19 09:25:28
(7 months ago)
Attempted brute force login to web vpn 36 time(s); last attempt for 2025.10.19 is noted in report ti ...
show more
Attempted brute force login to web vpn 36 time(s); last attempt for 2025.10.19 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-18 16:57:52
(7 months ago)
Attempted brute force login to web vpn 90 time(s); last attempt for 2025.10.18 is noted in report ti ...
show more
Attempted brute force login to web vpn 90 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force