π©πͺ
bescared
2026-07-20 20:56:44
(1 week ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-07-20 20:22:18
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-07-19 21:59:49
(1 week ago)
Auto-ban: >3000 req/min op 2026-07-19
Web App Attack
SSH
Hacking
πΊπΈ
daveoctober
2026-07-19 18:57:48
(1 week ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-07-19 17:06:31
(1 week ago)
Try to access /.git/HEAD
Web App Attack
π©πͺ
Hazzard
2026-05-21 19:57:00
(2 months ago)
(wordpress) Failed wordpress login from 104.207.48.50 (BR/Brazil/SΓ£o Paulo/SΓ£o Paulo/-/[redacted]): ...
show more
(wordpress) Failed wordpress login from 104.207.48.50 (BR/Brazil/SΓ£o Paulo/SΓ£o Paulo/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
π©πͺ
iNetWorker
2026-05-21 17:44:03
(2 months ago)
trolling for resource vulnerabilities
Web App Attack
π¬π§
PeravixGroup
2026-05-07 10:00:12
(2 months ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2026-01-15 01:13:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 20:13:22.740815 2026] [security2:error] [pid 973819:tid 973819] [client 104.207.48.50:24007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyber507.net"] [uri "/.git/HEAD"] [unique_id "aWg_MrfRhd9c2e0zRb99zQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 08:37:32
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:37:27.997338 2025] [security2:error] [pid 3738190:tid 3738260] [client 104.207.48.50:31831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.eliteproductions.tv"] [uri "/.git/HEAD"] [unique_id "aSa8R9ynXzP7IZS7N5-pPQAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 06:45:55
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:45:49.945739 2025] [security2:error] [pid 23584:tid 23584] [client 104.207.48.50:23409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.exploratorymusic.net"] [uri "/.git/HEAD"] [unique_id "aSaiHTJtPyeuMg9UmdKEjwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-24 11:05:13
(8 months ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 09:16:12
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:16:08.372088 2025] [security2:error] [pid 12232:tid 12232] [client 104.207.48.50:43507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.visionremota.info"] [uri "/.svn/wc.db"] [unique_id "aSQiWFIapi0xidiGL_2eDgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 07:41:54
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:41:46.227969 2025] [security2:error] [pid 26046:tid 26046] [client 104.207.48.50:22745] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aethena.org"] [uri "/.svn/wc.db"] [unique_id "aSQMOmbinHsaaEjuz7pW0gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:26:01
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:25:57.441935 2025] [security2:error] [pid 14843:tid 14868] [client 104.207.48.50:56535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aglsolidwaste.com"] [uri "/.svn/wc.db"] [unique_id "aSPeVV0D_Mes39tIl2r3WQAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack