๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ช๐ธ
10dencehispahard SL
2026-01-26 07:41:25
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฑ๐ป
garmtech.com
2025-11-26 03:23:56
(6 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:53:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:53:25.896326 2025] [security2:error] [pid 3815267:tid 3815267] [client 104.207.52.55:31543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bpcompany.net"] [uri "/.git/HEAD"] [unique_id "aSQrFTwE1LgXDT1LnDV6hAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:00:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:00:36.621855 2025] [security2:error] [pid 26784:tid 26784] [client 104.207.52.55:24429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.opticasprisma.com"] [uri "/.env"] [unique_id "aSQetKAdoGScgnqu3-IfCwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:12:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:12:06.165698 2025] [security2:error] [pid 4133561:tid 4133578] [client 104.207.52.55:17167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.philipjnielsen-drafting-design.com"] [uri "/.env"] [unique_id "aSP3Ns6lE8qghk7QOEVfHAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:43:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:43:01.021720 2025] [security2:error] [pid 32389:tid 32389] [client 104.207.52.55:58329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zemincollection.chevronparkett.com"] [uri "/.svn/wc.db"] [unique_id "aSPiVf7AYN7-K87e7NiLaAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2025-10-27 12:57:55
(7 months ago)
Unauthorized connection to SSH port 22
Port Scan
Hacking
SSH
Anonymous
2025-10-27 00:02:23
(7 months ago)
SSH BruteForce attack
SSH
Anonymous
2025-10-26 16:43:52
(7 months ago)
2025-10-26T17:43:49.084947 localhost.localdomain sshd[936887]: pam_unix(sshd:auth): authentication f ...
show more
2025-10-26T17:43:49.084947 localhost.localdomain sshd[936887]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.207.52.55
2025-10-26T17:43:51.085416 localhost.localdomain sshd[936887]: Failed password for invalid user [email protected] from 104.207.52.55 port 51521 ssh2
...
show less
Brute-Force
SSH
๐ณ๐ฑ
EGP Abuse Dept
2025-10-26 07:47:47
(7 months ago)
Unauthorized connection to SSH port 22
Port Scan
Hacking
SSH
Anonymous
2025-10-15 11:37:33
(7 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
oncord
2025-10-13 14:53:47
(7 months ago)
Form spam
Web Spam
๐ฉ๐ช
Packets-Decreaser.NET
2025-10-07 17:14:06
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-04-07 02:09:42
(1 year ago)
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force