Anonymous
2026-06-18 18:15:45
(9 hours ago)
Web attack blocked by Wordfence on www.charlesquaedvlieg.nl (1 hit). Reported by CRMON.
Web App Attack
๐บ๐ธ
xmission.com
2026-06-16 20:45:13
(2 days ago)
104.207.48.65 - - [16/Jun/2026:14:45:12 -0600] "POST /xmlrpc.php HTTP/1.1" 200 413 "https://www.goog ...
show more
104.207.48.65 - - [16/Jun/2026:14:45:12 -0600] "POST /xmlrpc.php HTTP/1.1" 200 413 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-12 01:50:28
(1 week ago)
(y4) Failed scan -byebye- from 104.207.48.65 (BR/Brazil/-): (CF_ENABLE)
Hacking
๐ฒ๐น
Malta
2026-06-10 11:22:08
(1 week ago)
104.207.48.65 - - [10/Jun/2026:13:22:08 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh ...
show more
104.207.48.65 - - [10/Jun/2026:13:22:08 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐ซ๐ท
ELYAZ
2026-06-10 02:14:21
(1 week ago)
(y4) Failed scan -byebye- from 104.207.48.65 (BR/Brazil/-): (CF_ENABLE)
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 19:45:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 14:45:48.554407 2026] [security2:error] [pid 27714:tid 27714] [client 104.207.48.65:51673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gaeltv.com"] [uri "/.env.save"] [unique_id "aYo5bKrOmltfH9BxG1NXEgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 18:40:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 13:40:46.741591 2026] [security2:error] [pid 2327820:tid 2327820] [client 104.207.48.65:21309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fvsllc.com"] [uri "/admin/.env"] [unique_id "aYoqLrlvTYi493ypsChMCQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 17:58:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 12:58:32.610189 2026] [security2:error] [pid 20613:tid 20613] [client 104.207.48.65:12989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furballaudio.com"] [uri "/.env.local"] [unique_id "aYogSHfMlItOu7B04oKRYQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 17:16:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 12:15:59.952914 2026] [security2:error] [pid 13185:tid 13185] [client 104.207.48.65:54077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fulltime-life.com"] [uri "/.env"] [unique_id "aYoWT6AP0VCCbt9KFpAdbQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 01:21:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 20:21:37.407619 2026] [security2:error] [pid 200473:tid 200473] [client 104.207.48.65:16695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftiptondds.com"] [uri "/.env.save"] [unique_id "aYk2oaIAF0EyDWrtWna99AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 21:09:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 16:09:19.235611 2025] [security2:error] [pid 7717:tid 7717] [client 104.207.48.65:19015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kidswithcamerasmovie.com"] [uri "/.svn/wc.db"] [unique_id "aVBK_4pQW9zOv0TZHBZOpAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 18:16:17
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 13:16:12.050096 2025] [security2:error] [pid 966:tid 966] [client 104.207.48.65:25623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cabwebs.com"] [uri "/.svn/wc.db"] [unique_id "aVAibDsA2YVgoNb7SYRaDwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 17:54:01
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 12:53:56.041319 2025] [security2:error] [pid 30598:tid 30598] [client 104.207.48.65:17943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coconut-homes.com"] [uri "/.svn/wc.db"] [unique_id "aVAdNLI5BQSMiHpfqmZgygAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 17:22:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 12:22:51.047569 2025] [security2:error] [pid 6034:tid 6034] [client 104.207.48.65:16493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruanyes.com"] [uri "/.git/HEAD"] [unique_id "aVAV6yIA_QkJVuaWshug4AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
_ArminS_
2025-12-26 05:31:48
(5 months ago)
WEB-Scan 48905:80 detected 2025.12.26 06:31:48
blocked until 2026.02.13 23:34:35
Port Scan