πΊπΈ
TPI-Abuse
2026-02-21 14:55:07
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 09:55:00.148146 2026] [security2:error] [pid 24853:tid 24853] [client 104.207.50.109:33091] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||heinsohn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "heinsohn.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZnHRNH-YH-dP62awDwOEAAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-20 03:32:50
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 22:32:43.136584 2026] [security2:error] [pid 7378:tid 7378] [client 104.207.50.109:58989] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alan-ip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alan-ip.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZfV24KqNLu5Bz2Y3HvezgAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-09 21:56:19
(4 months ago)
104.207.50.109 - - [09/Feb/2026:21:56:02 +0000] "GET /.env.local HTTP/1.1" 302 3410 "-" "Mozilla/5.0 ...
show more
104.207.50.109 - - [09/Feb/2026:21:56:02 +0000] "GET /.env.local HTTP/1.1" 302 3410 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 21:34:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:34:10.950059 2026] [security2:error] [pid 27719:tid 27719] [client 104.207.50.109:57969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gardnercastle.com"] [uri "/api/.git/config"] [unique_id "aYpS0qlfg8OcWtMVYdQ_pwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 18:55:04
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 13:54:58.290718 2026] [security2:error] [pid 12363:tid 12363] [client 104.207.50.109:41745] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fydelity.net"] [uri "/frontend/.env"] [unique_id "aYotgkAAsVEvqyqyhS9FsgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 18:37:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 13:37:28.397048 2026] [security2:error] [pid 8358:tid 8358] [client 104.207.50.109:13119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuzzyecho.com"] [uri "/app/.env"] [unique_id "aYopaK1Zr_M55yk2syeLYwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 09:22:28
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 04:22:23.261676 2026] [security2:error] [pid 19339:tid 19468] [client 104.207.50.109:64169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "g3-contracting.com"] [uri "/config/.env"] [unique_id "aYmnT4gSOxwRKbWl7oL0TgAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2025-12-26 02:10:48
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-11-24 08:32:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:32:26.498973 2025] [security2:error] [pid 1694:tid 1694] [client 104.207.50.109:21543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.boatpeople.org"] [uri "/.git/HEAD"] [unique_id "aSQYGhrwEnfHa6CycKR8SQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:34:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:34:54.919048 2025] [security2:error] [pid 31386:tid 31386] [client 104.207.50.109:57975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mcacpas.com"] [uri "/.env"] [unique_id "aSPgbhrlTCP07JVPNyy4jQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
octageeks.com
2025-10-27 04:07:27
(7 months ago)
Wordpress malicious attack:[sshd]
Web App Attack
Anonymous
2025-10-25 00:29:45
(7 months ago)
fail2ban:piguard2:14,18
Port Scan
Brute-Force
π©πͺ
cloudmax
2025-10-23 15:14:11
(7 months ago)
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnera ...
show more
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnerability probing
show less
Port Scan
π³π±
mdekock
2025-10-23 07:49:43
(7 months ago)
Oct 23 09:49:39 excalibur sshd[1432489]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show more
Oct 23 09:49:39 excalibur sshd[1432489]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.207.50.109
Oct 23 09:49:41 excalibur sshd[1432489]: Failed password for invalid user [email protected] from 104.207.50.109 port 50243 ssh2
Oct 23 09:49:42 excalibur sshd[1432489]: Connection closed by invalid user [email protected] 104.207.50.109 port 50243 [preauth]
...
show less
Brute-Force
SSH
Anonymous
2025-10-10 20:13:02
(8 months ago)
Attempted brute force login to web vpn 145 time(s); last attempt for 2025.10.10 is noted in report t ...
show more
Attempted brute force login to web vpn 145 time(s); last attempt for 2025.10.10 is noted in report timestamp
show less
Hacking
Brute-Force