๐บ๐ธ
ctrlpew
2026-05-19 01:01:08
(3 weeks ago)
WordPress login brute-force botnet targeting ctrlpew.com. Distributed IPs cycling every 3 seconds wi ...
show more
WordPress login brute-force botnet targeting ctrlpew.com. Distributed IPs cycling every 3 seconds with UA rotation. All attempts against non-existent usernames. 2026-05-18.
show less
Brute-Force
Web App Attack
๐ซ๐ท
tecnicorioja
2026-05-15 22:00:13
(4 weeks ago)
wp-login attack [15/May/2026:20:53:40
Brute-Force
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-05-01 23:10:20
(1 month ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/104.207.51.113
2026-05 ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/104.207.51.113
2026-05-01 06:56:42 /
2026-05-01 06:49:48 /
2026-05-01 06:30:54 /
show less
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 06:54:39
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 01:54:32.169013 2026] [security2:error] [pid 32484:tid 32484] [client 104.207.51.113:57271] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||igolfallday.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "igolfallday.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZViKFekMW2DEbVoETo_gwAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-02-13 09:09:31
(4 months ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
๐ฎ๐ฉ
Burayot
2026-02-13 06:08:19
(4 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 104.207.51.113 (GB/United Kingdom/- ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 104.207.51.113 (GB/United Kingdom/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 06:00:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 01:00:09.474395 2026] [security2:error] [pid 2718253:tid 2718253] [client 104.207.51.113:62737] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konzel.com"] [uri "/app/.env"] [unique_id "aY696Y6alFrlcErdEkcitgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-02-13 04:35:42
(4 months ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 02:37:03
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 21:36:55.646712 2026] [security2:error] [pid 5900:tid 5900] [client 104.207.51.113:36195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kenmalone.com"] [uri "/.env"] [unique_id "aY6OR_B0ClywXSpKgu64hwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 01:38:40
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 20:38:34.646160 2026] [security2:error] [pid 4013:tid 4013] [client 104.207.51.113:16371] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexetjeremy.com"] [uri "/.git/config"] [unique_id "aY6AmmAgtDy3lpPIuHZNbgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 18:06:35
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 13:06:29.220757 2026] [security2:error] [pid 17958:tid 17958] [client 104.207.51.113:21607] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eclipseespana.com"] [uri "/.git/config"] [unique_id "aY4WpeYrr432fSdH_YGnzAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
6o6ep
2026-02-12 17:51:54
(4 months ago)
HEAD / HTTP/1.1
Port Scan
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-12 16:05:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 11:05:34.318502 2026] [security2:error] [pid 4748:tid 4792] [client 104.207.51.113:44337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bobchaos.com"] [uri "/.git/config"] [unique_id "aY36To6dgWpHYQt3aeDK4AAAAg0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 15:11:28
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 10:11:19.434850 2026] [security2:error] [pid 26464:tid 26464] [client 104.207.51.113:11193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buanamegah.com"] [uri "/.git/config"] [unique_id "aY3tl5ATysjFYrwo0DPE9AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack