๐ฉ๐ช
LRob.fr
2026-03-04 01:00:31
(3 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2026-02-27 21:09:19
(3 months ago)
"POST /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 20:55:46
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 15:55:41.581762 2026] [security2:error] [pid 15294:tid 15294] [client 104.207.55.19:41829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ardeeapps.com"] [uri "/site/.git/config"] [unique_id "aYzszRvXlNfCXdai2LrS7QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 22:59:08
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-10 06:08:01
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 01:07:52.944726 2026] [security2:error] [pid 13426:tid 13426] [client 104.207.55.19:17973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail-rfinder.com"] [uri "/.git/config"] [unique_id "aYrLOB6ecq9Xejj7MjZnwQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:28:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:28:02.458586 2026] [security2:error] [pid 9037:tid 9037] [client 104.207.55.19:12211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirklandhighlands.org"] [uri "/backend/.env"] [unique_id "aYqlwucgOGJsr8Aw1bhBlgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 01:01:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 20:01:52.455233 2026] [security2:error] [pid 7424:tid 7424] [client 104.207.55.19:12285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humbliaslaw.com"] [uri "/v2/.git/config"] [unique_id "aYqDgDJWjj-W7-3NmPeuqAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:06:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:06:44.708446 2026] [security2:error] [pid 1733:tid 1733] [client 104.207.55.19:11833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathyquan.com"] [uri "/admin/.git/config"] [unique_id "aYpadNO6W64QZVM_mCn8oAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:24:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:24:07.206669 2026] [security2:error] [pid 2069:tid 2069] [client 104.207.55.19:37817] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kanata.ws"] [uri "/api/.env"] [unique_id "aYpCZwzhTpXD0EB93ekobAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Jean Valjean
2026-01-04 17:49:55
(5 months ago)
Fail2ban Caboom : xmlrpc.php Abuse
SQL Injection
Web App Attack
Anonymous
2025-11-27 13:45:31
(6 months ago)
Attempted brute force login to web vpn 2131 time(s); last attempt for 2025.11.27 is noted in report ...
show more
Attempted brute force login to web vpn 2131 time(s); last attempt for 2025.11.27 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-11-18 21:22:56
(6 months ago)
Attempted brute force login to web vpn 290 time(s); last attempt for 2025.11.18 is noted in report t ...
show more
Attempted brute force login to web vpn 290 time(s); last attempt for 2025.11.18 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-07 11:39:54
(1 year ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-06 19:25:17
(1 year ago)
Attempted brute force login to web vpn 5 time(s); last attempt for 2025.04.06 is noted in report tim ...
show more
Attempted brute force login to web vpn 5 time(s); last attempt for 2025.04.06 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-05 03:23:58
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.04.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.04.05 is noted in report timestamp
show less
Hacking
Brute-Force