๐ซ๐ท
tecnicorioja
2026-05-15 22:00:13
(3 weeks ago)
wp-login attack [15/May/2026:20:53:46
Brute-Force
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 21:54:38
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 16:54:31.259441 2026] [security2:error] [pid 10331:tid 10331] [client 104.207.50.208:30795] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greenmountainfeeds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greenmountainfeeds.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZjYF0crQDcMLSjsul6OAgAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LARL-Stompro-2024
2026-01-30 06:40:09
(4 months ago)
Evergreen ILS - Mylist Bot Abuse - HTTP Port 443 - Fake UserAgent. Requests:1
Bad Web Bot
๐ฉ๐ช
bsoft.de
2026-01-20 15:02:47
(4 months ago)
Blocked because of abusive behavior
DDoS Attack
๐ฎ๐ฉ
Burayot
2026-01-20 13:14:35
(4 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 104.207.50.208 (GB/United Kingdom/- ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 104.207.50.208 (GB/United Kingdom/-): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-01-03 13:37:26
(5 months ago)
Attempted brute force login to web vpn 18 time(s); last attempt for 2026.01.03 is noted in report ti ...
show more
Attempted brute force login to web vpn 18 time(s); last attempt for 2026.01.03 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-11-27 12:03:59
(6 months ago)
Attempted brute force login to web vpn 198 time(s); last attempt for 2025.11.27 is noted in report t ...
show more
Attempted brute force login to web vpn 198 time(s); last attempt for 2025.11.27 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-11-25 18:56:32
(6 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:08:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:08:38.561820 2025] [security2:error] [pid 17670:tid 17670] [client 104.207.50.208:54789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.winterspring.net"] [uri "/.git/HEAD"] [unique_id "aSVH5uMhu_tD1i4Irl_gbgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:55:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:55:49.019361 2025] [security2:error] [pid 26349:tid 26349] [client 104.207.50.208:48457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.numberseven.okwellbeing.com"] [uri "/.svn/wc.db"] [unique_id "aSU21bs4J5TPwIcORQikKgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:02:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:02:49.433676 2025] [security2:error] [pid 4335:tid 4335] [client 104.207.50.208:19575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dannyvanrijswijk.com"] [uri "/.git/HEAD"] [unique_id "aSUqaecEj3-wYMB3aMS8xAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:37:45
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:37:36.833836 2025] [security2:error] [pid 16377:tid 16377] [client 104.207.50.208:19079] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.groundwateradvertising.g-h2o.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.groundwateradvertising.g-h2o.com"] [uri "/.svn/wc.db"] [unique_id "aSUkgEIFz3wQFZiaHzN2UQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:31:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:31:46.631989 2025] [security2:error] [pid 10669:tid 10669] [client 104.207.50.208:30071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.roachranch.com"] [uri "/.env"] [unique_id "aSUVEkpsv3VL0SFFNbYOiAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:08:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:08:09.031317 2025] [security2:error] [pid 27010:tid 27010] [client 104.207.50.208:17281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.carolineburkedesigns.com"] [uri "/.git/HEAD"] [unique_id "aSUPibQbIYNDIkgJw2MyRwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack