๐บ๐ธ
TRoden
2026-01-10 03:18:43
(4 months ago)
Geo Block Plugin: Escalation flag(s): rce_attempt
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-29 06:03:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:03:24.127211 2025] [security2:error] [pid 1261421:tid 1261421] [client 104.207.56.32:45791] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matronasoy.com"] [uri "/.env"] [unique_id "aVIZrJ97LF3opUQ3SdH71AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-21 12:59:39
(5 months ago)
Attempted brute force login to web vpn 164 time(s); last attempt for 2025.12.21 is noted in report t ...
show more
Attempted brute force login to web vpn 164 time(s); last attempt for 2025.12.21 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-12-19 23:28:54
(5 months ago)
Attempted brute force login to web vpn 162 time(s); last attempt for 2025.12.19 is noted in report t ...
show more
Attempted brute force login to web vpn 162 time(s); last attempt for 2025.12.19 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-26 08:37:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:37:18.727146 2025] [security2:error] [pid 9541:tid 9597] [client 104.207.56.32:44581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stateabbreviationlist.com"] [uri "/.svn/wc.db"] [unique_id "aSa8PmMy3HNq1n2SMlt7hAAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:16:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:16:31.603567 2025] [security2:error] [pid 13273:tid 13273] [client 104.207.56.32:44829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.toytractorrepair.com"] [uri "/.git/HEAD"] [unique_id "aSVXz5jtYnx7q5Kt0vszqQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:53:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:53:27.342946 2025] [security2:error] [pid 31695:tid 31695] [client 104.207.56.32:14469] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whitesquirrelholdings.hal.dance"] [uri "/.env"] [unique_id "aSVSZ9F60SfDXVE5s5-niAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:29:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:29:19.592180 2025] [security2:error] [pid 11778:tid 11778] [client 104.207.56.32:50329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "battlestem.com"] [uri "/.env"] [unique_id "aSQXXzUzu48wPnywj9y2bAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:50:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:50:45.601290 2025] [security2:error] [pid 14415:tid 14415] [client 104.207.56.32:42329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bella-vista.com"] [uri "/.env"] [unique_id "aSQOVQY12d6rgSvbFlxdRwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:56:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:56:33.561736 2025] [security2:error] [pid 12125:tid 12125] [client 104.207.56.32:23325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rxrepconnect.circlehealthcaregroup.com"] [uri "/.svn/wc.db"] [unique_id "aSPlgYPULV4Dhkxj1HzKpwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:13:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:13:12.622503 2025] [security2:error] [pid 19731:tid 19731] [client 104.207.56.32:21069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.louiserevans.com"] [uri "/.git/HEAD"] [unique_id "aSPbWAVBeoFtLRelRdjkOAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 00:28:05
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 19:28:02.387305 2025] [security2:error] [pid 18313:tid 18313] [client 104.207.56.32:58617] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.smart1services.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.smart1services.com"] [uri "/s3cmd.ini"] [unique_id "aRKDEicNAJsO-oS3JwQBeAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oncord
2025-04-08 05:57:11
(1 year ago)
Form spam
Web Spam
Anonymous
2025-04-07 10:33:22
(1 year ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-06 22:47:15
(1 year ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.06 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.06 is noted in report timestamp
show less
Hacking
Brute-Force