π³π±
ParaBug
2026-07-17 15:04:19
(1 week ago)
104.207.57.59 - - [17/Jul/2026:17:04:18 +0200] "GET http://antik-wagon.com/news-sitemap.xml HTTP/1.1 ...
show more
104.207.57.59 - - [17/Jul/2026:17:04:18 +0200] "GET http://antik-wagon.com/news-sitemap.xml HTTP/1.1" 301 501 "-" "Mozilla/5.0"
...
show less
Phishing
Brute-Force
Web App Attack
π«π·
Sklurk
2026-07-08 00:33:41
(2 weeks ago)
Web App Attack
Web App Attack
π©πͺ
4server
2026-05-25 15:28:59
(1 month ago)
[MonMay2517:28:53.3833052026][security2:error][pid100813:tid100925][client104.207.57.59:0]ModSecurit ...
show more
[MonMay2517:28:53.3833052026][security2:error][pid100813:tid100925][client104.207.57.59:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"restaurantgandria.ch\"][uri\"/xmlrpc.php\"][unique_id\"ahRqtRi3jhRoCgtlvwayxwAAAMw\"]
show less
Port Scan
Brute-Force
Web App Attack
π«π·
ingroscart.it
2026-03-17 07:01:51
(4 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 104.207.57.59 (DE/Ge ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 104.207.57.59 (DE/Germany/-)
show less
Bad Web Bot
Anonymous
2026-03-12 05:09:36
(4 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2026-01-05 20:14:25
(6 months ago)
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-11-26 23:07:51
(7 months ago)
Attempted brute force login to web vpn 18 time(s); last attempt for 2025.11.26 is noted in report ti ...
show more
Attempted brute force login to web vpn 18 time(s); last attempt for 2025.11.26 is noted in report timestamp
show less
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2025-11-26 08:35:56
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:35:52.553931 2025] [security2:error] [pid 8189:tid 8189] [client 104.207.57.59:35337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ikutabukkyokai.com"] [uri "/.svn/wc.db"] [unique_id "aSa76O4kK_bxMZIfe2WmbQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 07:21:30
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 02:21:23.570455 2025] [security2:error] [pid 2521454:tid 2521454] [client 104.207.57.59:41679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tjwus.com"] [uri "/.svn/wc.db"] [unique_id "aSaqc-hn-yh6dYNkVAamIwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 05:27:28
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:27:20.096243 2025] [security2:error] [pid 1872:tid 1872] [client 104.207.57.59:58311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.chadfishman.com"] [uri "/.env"] [unique_id "aSaPuF00mkWAKrVD0mPCLQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 01:35:36
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:35:30.144664 2025] [security2:error] [pid 27169:tid 27169] [client 104.207.57.59:46419] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.killigrewcompany.com"] [uri "/.git/HEAD"] [unique_id "aSZZYiys10V1hRl9uqMQ4wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 00:35:25
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:35:22.036632 2025] [security2:error] [pid 22086:tid 22274] [client 104.207.57.59:29543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crosstheatre.pwrcoupling.com"] [uri "/.svn/wc.db"] [unique_id "aSZLShCcVYSuHH558FyCBgAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:21:57
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.57.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:21:50.457551 2025] [security2:error] [pid 18854:tid 18854] [client 104.207.57.59:31949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.brbcoin.com"] [uri "/.env"] [unique_id "aSPdXtfyqQrOZr7bFYsQOwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Rip
2025-11-02 10:55:54
(8 months ago)
Authentication attack attempt. CMS Brute Force - Access Forbidden
Brute-Force
Web App Attack
Anonymous
2025-04-07 13:26:52
(1 year ago)
Attempted brute force login to web vpn 5 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 5 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force