๐ซ๐ท
ELYAZ
2026-05-31 23:37:38
(5 days ago)
(y4) Failed scan -byebye- from 104.207.56.80 (DE/Germany/-): (CF_ENABLE)
Hacking
Anonymous
2026-05-31 05:02:47
(6 days ago)
[server.tmg.gr] httpd-login-spray-site: sites=add2021.gr; logs=/var/log/httpd/domains/add2021.gr.log ...
show more
[server.tmg.gr] httpd-login-spray-site: sites=add2021.gr; logs=/var/log/httpd/domains/add2021.gr.log; samples=site_wide=true | distinct_ips=16 | /wp-login.php
show less
Hacking
Web App Attack
๐ฉ๐ช
F242
2026-05-28 02:39:43
(1 week ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
oralunal
2026-05-26 13:28:03
(1 week ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
Anonymous
2026-05-26 04:50:01
(1 week ago)
[server.tmg.gr] httpd-login-spray-site: sites=amli2018.com; logs=/var/log/httpd/domains/amli2018.com ...
show more
[server.tmg.gr] httpd-login-spray-site: sites=amli2018.com; logs=/var/log/httpd/domains/amli2018.com.log; samples=site_wide=true | distinct_ips=45 | /wp-login.php
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-26 04:34:23
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-05-08 18:52:26
(4 weeks ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:31:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:31:08.925331 2025] [security2:error] [pid 27253:tid 27253] [client 104.207.56.80:34427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.eaglespiritproductions.com"] [uri "/.git/HEAD"] [unique_id "aSVNLEvmcdFlsrsHmPKsEAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-25 05:53:25
(6 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:10:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:10:54.464310 2025] [security2:error] [pid 26400:tid 26400] [client 104.207.56.80:32851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mlsdirect.xyz"] [uri "/.svn/wc.db"] [unique_id "aSUsTjdDstV1EWERcJJnqQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:06:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:06:45.939415 2025] [security2:error] [pid 20336:tid 20336] [client 104.207.56.80:19271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crochetdoilies.com"] [uri "/.env"] [unique_id "aSUPNUc5xRejY4iTN4YjsgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:24:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:22:26.884298 2025] [security2:error] [pid 27184:tid 27184] [client 104.207.56.80:26305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gundiahgazette.com.au"] [uri "/.svn/wc.db"] [unique_id "aSQHso9E3CyyB_r2GhTueAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 15:04:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 10:04:23.649285 2025] [security2:error] [pid 3794:tid 3794] [client 104.207.56.80:31955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thunder-kings.hodlmoser.com"] [uri "/.env"] [unique_id "aRiWd1xf1iH9MLlmCxV6vgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 00:29:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.56.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 19:29:05.059012 2025] [security2:error] [pid 26377:tid 26377] [client 104.207.56.80:39643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bouldercorporate.com"] [uri "/.env"] [unique_id "aRfJUeRiU5Ya8XOMMkPz5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack