๐ฌ๐ง
PeravixGroup
2026-05-12 04:19:39
(3 weeks ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ฌ๐ง
PeravixGroup
2026-05-08 17:23:28
(4 weeks ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ซ๐ท
COMAITE
2026-04-03 05:23:35
(2 months ago)
SQL injection attempt from 104.207.48.180.
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-21 07:36:24
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
myagent.site
2026-01-13 11:55:41
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-07 19:37:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 14:37:41.411844 2026] [security2:error] [pid 21029:tid 21029] [client 104.207.48.180:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jspsf.com"] [uri "/.svn/wc.db"] [unique_id "aV62BYWBmDXOVrZT0w3kXwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:12
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-29 04:54:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:54:43.574649 2025] [security2:error] [pid 31396:tid 31396] [client 104.207.48.180:58343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dodgersboosterclub.com"] [uri "/.svn/wc.db"] [unique_id "aVIJk2Ja2Ts3A2Dus-u0ggAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 16:24:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 11:24:20.810973 2025] [security2:error] [pid 8102:tid 8102] [client 104.207.48.180:43387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teamworkchristmascards.com"] [uri "/.git/HEAD"] [unique_id "aS8StMJPEH5Jx0AF7y4vggAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 08:24:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 03:24:20.134158 2025] [security2:error] [pid 12882:tid 12882] [client 104.207.48.180:42831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tradersworldmarket.com"] [uri "/.git/HEAD"] [unique_id "aS6iNJiMkjUry1cJOcNJRwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 08:02:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 03:02:49.488058 2025] [security2:error] [pid 26221:tid 26221] [client 104.207.48.180:43063] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "connectigramme.com"] [uri "/.env"] [unique_id "aS6dKU1ZglAyXEiqebWOnAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:58:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:58:22.575893 2025] [security2:error] [pid 29604:tid 29604] [client 104.207.48.180:10969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "needtoorderforms.com"] [uri "/.env"] [unique_id "aS5__g-QoG8T6gTeE8BRkgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-25 12:03:01
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.48.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 25 08:02:57.193575 2025] [security2:error] [pid 32602:tid 32602] [client 104.207.48.180:29831] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wisewerks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wisewerks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPy8cbBtu2TiQ-3o4P0cigAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2025-10-18 12:31:38
(7 months ago)
MYH: Web Attack POST /wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2025-10-17 12:14:40
(7 months ago)
WordPress login attempt
Brute-Force