๐ธ๐ฎ
administrator
2026-06-02 22:14:37
(2 weeks ago)
2026-06-02 00:06:24,161 fail2ban.actions [1162]: NOTICE [ninjafirewall] Ban 104.207.57.189
2 ...
show more
2026-06-02 00:06:24,161 fail2ban.actions [1162]: NOTICE [ninjafirewall] Ban 104.207.57.189
2026-06-02 00:06:24,161 fail2ban.actions [1162]: NOTICE [ninjafirewall] Ban 104.207.57.189
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-05-11 05:12:29
(1 month ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ธ๐ฎ
administrator
2026-05-04 16:39:09
(1 month ago)
2026-04-10 20:36:53,010 fail2ban.actions [530353]: NOTICE [ninjafirewall] Ban 104.207.57.189 ...
show more
2026-04-10 20:36:53,010 fail2ban.actions [530353]: NOTICE [ninjafirewall] Ban 104.207.57.189
2026-05-04 18:22:03,486 fail2ban.actions [264717]: NOTICE [ninjafirewall] Ban 104.207.57.189
2026-04-10 20:36:53,010 fail2ban.actions [530353]: NOTICE [ninjafirewall] Ban 104.207.57.189
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-05-03 01:31:43
(1 month ago)
Honeypot detection: Memcached unauthorized access / amplification attempt on port 2375. Severity: HI ...
show more
Honeypot detection: Memcached unauthorized access / amplification attempt on port 2375. Severity: HIGH. Aaran.cloud
show less
Hacking
Exploited Host
๐ธ๐ช
KIDOS
2026-04-06 08:04:09
(2 months ago)
malicious activity
Web App Attack
๐จ๐ฟ
ptlab
2026-04-05 20:45:24
(2 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ซ๐ท
COMAITE
2026-03-28 13:13:49
(2 months ago)
SQL injection attempt from 104.207.57.189.
Web App Attack
๐ช๐ธ
librebit
2026-03-24 03:09:04
(2 months ago)
Brute force
Brute-Force
Anonymous
2026-02-10 04:31:22
(4 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-02-10 02:16:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:15:54.892306 2026] [security2:error] [pid 27819:tid 27819] [client 104.207.57.189:14097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killeramps.com"] [uri "/.env.production"] [unique_id "aYqU2kBVJkGHiSRuEKzf9wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:08:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:08:24.872946 2026] [security2:error] [pid 18579:tid 18579] [client 104.207.57.189:53333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homeschoolwv.com"] [uri "/.git/config"] [unique_id "aYo-uKA8cihN4pd1Qzke8wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-02 16:21:02
(4 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:53:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:53:22.018376 2025] [security2:error] [pid 4898:tid 4898] [client 104.207.57.189:50595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.genevainvestors.internetnameregistration.com"] [uri "/.git/HEAD"] [unique_id "aSbAAsR-2R5KLHgoFC3Y9gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:24:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:24:38.500511 2025] [security2:error] [pid 11263:tid 11263] [client 104.207.57.189:37545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buenasfrecuencias.circulodesonido.org"] [uri "/.svn/wc.db"] [unique_id "aSa5Rvmy6rfQrgoiIjBKvgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:01:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:01:32.581755 2025] [security2:error] [pid 4395:tid 4395] [client 104.207.57.189:50955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.arttechnology.net"] [uri "/.git/HEAD"] [unique_id "aSZDXL5Q8ZD2iqv2BxY5RgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack