๐ฌ๐ง
PeravixGroup
2026-06-09 23:08:25
(4 days ago)
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity ...
show more
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-02-11 17:42:46
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 12:42:38.416665 2026] [security2:error] [pid 29727:tid 29727] [client 104.207.50.175:42663] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||seariversummit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "seariversummit.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYy_jkPmOreRJwcwtaHU4QAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
geot
2026-01-17 21:33:42
(4 months ago)
GET /.aws/credentials HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
clapper
2026-01-17 08:29:36
(4 months ago)
(mod_security) mod_security (id:949110) triggered by 104.207.50.175 (GB/United Kingdom/-): 5 in the ...
show more
(mod_security) mod_security (id:949110) triggered by 104.207.50.175 (GB/United Kingdom/-): 5 in the last 3600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-17 06:08:00
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 01:07:53.799874 2026] [security2:error] [pid 66646:tid 66747] [client 104.207.50.175:23447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.emjayentertainmentdj.com"] [uri "/.env"] [unique_id "aWsnOW9MRXKGrYfAFBK59wAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 03:42:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 22:41:59.773342 2026] [security2:error] [pid 1056862:tid 1056862] [client 104.207.50.175:24713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saltcityprint.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aWmzhwsoYxDKYfyrG0RxGAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 02:47:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 21:47:27.471886 2026] [security2:error] [pid 24432:tid 24432] [client 104.207.50.175:33721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarawagnergrants.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aWmmv9ntb6H1KsWR7DgmRAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:42
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-29 09:23:21
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 04:23:17.924090 2025] [security2:error] [pid 13790:tid 13790] [client 104.207.50.175:40419] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dipseanet.com"] [uri "/.git/HEAD"] [unique_id "aVJIhdjLMUZS4FNQxE3d-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2025-12-29 09:05:07
(5 months ago)
tcp/80; Git HEAD reference exposure attempt: "GET /.git/HEAD" @ 2025-12-29T09:04:11Z [proxy]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 08:14:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 03:14:32.823170 2025] [security2:error] [pid 26295:tid 26295] [client 104.207.50.175:31019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konstantiasofokleous.com"] [uri "/.env"] [unique_id "aVI4aPInMLO9jEeo3vEvqAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 07:18:53
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 02:18:48.327093 2025] [security2:error] [pid 13108:tid 13108] [client 104.207.50.175:33939] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jitterbugperfume.com"] [uri "/.svn/wc.db"] [unique_id "aVIrWDqaLv55V69Q-rJI3gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:46:45
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:46:40.648587 2025] [security2:error] [pid 23902:tid 23902] [client 104.207.50.175:18839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compliancedepts.com"] [uri "/.svn/wc.db"] [unique_id "aVIVwBOxk_R1bOv6ceru8QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:43:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:43:30.493570 2025] [security2:error] [pid 3531:tid 3531] [client 104.207.50.175:39781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.alecmcatee.com"] [uri "/.git/HEAD"] [unique_id "aSQassOrPt9vZuSI9f1B0wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:07:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:07:16.066030 2025] [security2:error] [pid 3513358:tid 3513358] [client 104.207.50.175:46393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jeannieksmith.com"] [uri "/.svn/wc.db"] [unique_id "aSQSNMdYgS3r7x0YBBBBIAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack