๐บ๐ธ
drewf.ink
2026-08-29 20:16:03
(1 day ago)
[20:16] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[20:16] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
๐ซ๐ท
Sklurk
2026-07-31 01:42:17
(1 month ago)
Web App Attack
Web App Attack
๐ฉ๐ช
4server
2026-04-03 18:06:45
(4 months ago)
[FriApr0320:06:38.5289942026][security2:error][pid3997992:tid3998012][client104.207.54.13:0]ModSecur ...
show more
[FriApr0320:06:38.5289942026][security2:error][pid3997992:tid3998012][client104.207.54.13:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"159\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"restaurantgandria.ch\"][uri\"/wp-login.php\"][unique_id\"adABrtipF5z4tomsRAiVkAAAAFE\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-01-05 20:40:00
(7 months ago)
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-02 17:26:24
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 12:26:18.086830 2025] [security2:error] [pid 10640:tid 10640] [client 104.207.54.13:34749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorspainmanagement.com"] [uri "/.env"] [unique_id "aS8hOg48W4QZFF5-hbnquAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 13:00:34
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 08:00:24.345089 2025] [security2:error] [pid 24426:tid 24426] [client 104.207.54.13:39943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gabosoftware.com"] [uri "/.env"] [unique_id "aS7i6HtY6ip-6By13prz0QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 08:10:57
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 03:10:52.157292 2025] [security2:error] [pid 19305:tid 19305] [client 104.207.54.13:27855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "donutburger.com"] [uri "/.env"] [unique_id "aS6fDNE1nBnTaL5IMBfF7QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-12-02 06:03:44
(8 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-02 04:58:05
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:58:01.888184 2025] [security2:error] [pid 25334:tid 25334] [client 104.207.54.13:30363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blacktieokc.com"] [uri "/.env"] [unique_id "aS5x2QME59vPHEp4M3HTXwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 02:10:35
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 21:10:32.515339 2025] [security2:error] [pid 20608:tid 20608] [client 104.207.54.13:53665] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruralroutes.ca"] [uri "/.env"] [unique_id "aS5KmDisTr4GbuD5bWPTVwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:28:46
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:28:42.276712 2025] [security2:error] [pid 25106:tid 25156] [client 104.207.54.13:58025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.talenttourhrservices.com"] [uri "/.svn/wc.db"] [unique_id "aSQlSjsFdfAxnE8Jg1ZHtQAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:04:18
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:04:13.477199 2025] [security2:error] [pid 12103:tid 12139] [client 104.207.54.13:50703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3sacloud.potashbarn.com"] [uri "/.env"] [unique_id "aSQDbed3pxroRSWDTtpedAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:10:00
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:09:38.333145 2025] [security2:error] [pid 5943:tid 5943] [client 104.207.54.13:21893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ifilemuseum.title26.com"] [uri "/.git/HEAD"] [unique_id "aSPokmp-nNoCgTekQHQbcQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2025-10-15 07:47:22
(10 months ago)
WordPress login attempt
Brute-Force
Anonymous
2025-04-07 09:19:28
(1 year ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force