๐ซ๐ท
ELYAZ
2026-06-02 02:31:43
(3 days ago)
(y4) Failed scan -byebye- from 104.207.51.8 (GB/United Kingdom/-): (CF_ENABLE)
Hacking
๐ฉ๐ช
FeG Deutschland
2026-05-31 01:18:35
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ซ๐ท
ELYAZ
2026-05-30 17:44:09
(5 days ago)
(y4) Failed scan -byebye- from 104.207.51.8 (GB/United Kingdom/-): (CF_ENABLE)
Hacking
Anonymous
2026-05-30 04:20:14
(6 days ago)
Web attack blocked by Wordfence on kunstkringhenrijonas.nl (3 hits). Reported by CRMON.
Web App Attack
Anonymous
2026-05-29 02:09:04
(1 week ago)
[ssd5.kdns.gr] httpd-login-spray-site: sites=hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; s ...
show more
[ssd5.kdns.gr] httpd-login-spray-site: sites=hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; samples=site_wide=true | distinct_ips=22 | /wp-login.php
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 07:50:22
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 02:50:15.299806 2026] [security2:error] [pid 24807:tid 24807] [client 104.207.51.8:14083] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||utd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "utd.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZgSN7UAvBXBPi8x7S0EJgAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 10:24:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:24:54.389758 2025] [security2:error] [pid 12796:tid 12796] [client 104.207.51.8:29139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desertautoworks.com"] [uri "/.env"] [unique_id "aSbVduIYo0JdI_sLqks7wQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 10:00:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 04:59:56.906238 2025] [security2:error] [pid 3931:tid 3931] [client 104.207.51.8:45275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.enfiestate.com"] [uri "/.env"] [unique_id "aSbPnKxv3TnSEPMT9pJPVAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 09:33:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 04:33:21.948758 2025] [security2:error] [pid 4864:tid 4864] [client 104.207.51.8:54307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.janicestewart.net"] [uri "/.svn/wc.db"] [unique_id "aSbJYT0IYUW22JiJgSFCIgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-26 07:44:23
(6 months ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
๐ฉ๐ช
barbarella
2025-11-25 02:12:17
(6 months ago)
Configuration snooping (GET /.git/HEAD)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 09:00:53
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.51.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 04:00:47.593479 2025] [security2:error] [pid 26269:tid 26269] [client 104.207.51.8:50725] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.foundintranslation.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.foundintranslation.net"] [uri "/s3cmd.ini"] [unique_id "aRGpvyaRi9M3gS-sX_fMeQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-10-13 12:10:45
(7 months ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2025-10-11 21:50:51
(7 months ago)
Form spam
Web Spam
Anonymous
2025-04-07 08:09:23
(1 year ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force