🇫🇷
Sklurk
2026-08-10 02:12:37
(2 weeks ago)
Web App Attack
Web App Attack
🇪🇸
librebit
2026-06-26 02:15:25
(2 months ago)
Brute force
Brute-Force
🇪🇸
librebit
2026-06-24 10:07:48
(2 months ago)
Brute force
Brute-Force
🇲🇹
Malta
2026-05-16 22:17:32
(3 months ago)
104.207.60.12 - - [17/May/2026:00:17:32 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
104.207.60.12 - - [17/May/2026:00:17:32 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
show less
Hacking
Web App Attack
VPN IP
Anonymous
2026-01-27 22:17:43
(7 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2026-01-05 20:25:59
(7 months ago)
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
🇱🇻
garmtech.com
2025-12-04 00:47:02
(8 months ago)
IM360 WAF: Attempt to upload malware
Hacking
Anonymous
2025-11-27 11:48:40
(9 months ago)
Attempted brute force login to web vpn 198 time(s); last attempt for 2025.11.27 is noted in report t ...
show more
Attempted brute force login to web vpn 198 time(s); last attempt for 2025.11.27 is noted in report timestamp
show less
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2025-11-26 09:47:58
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 04:47:53.248735 2025] [security2:error] [pid 24360:tid 24360] [client 104.207.60.12:38709] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.presucad.com"] [uri "/.env"] [unique_id "aSbMyRwQccgVBKFpIDqpsgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 02:31:57
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:31:49.918512 2025] [security2:error] [pid 26214:tid 26214] [client 104.207.60.12:43619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.highaltitudebaking.com"] [uri "/.svn/wc.db"] [unique_id "aSZmlfnk8XiGWl8linXqxgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 01:02:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:02:00.708868 2025] [security2:error] [pid 3365543:tid 3365655] [client 104.207.60.12:22713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rush.piazzala.com"] [uri "/.env"] [unique_id "aSZRiGzJ-U6IElkF6xMt4QAAAcY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 00:15:11
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:15:08.878514 2025] [security2:error] [pid 21477:tid 21477] [client 104.207.60.12:39781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accountancy-career.selfdirecteddiscovery.org"] [uri "/.svn/wc.db"] [unique_id "aSZGjLX74-qQnwhlnxB5NwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2025-11-25 14:01:05
(9 months ago)
Request content type is not allowed by policy. Match of "within %{tx.allowed_request_content_type}" ...
show more
Request content type is not allowed by policy. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. (920420-193)
show less
Hacking
Web App Attack
🇪🇸
10dencehispahard SL
2025-11-19 07:15:18
(9 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
🇺🇸
TPI-Abuse
2025-11-11 03:42:08
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.60.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 22:42:01.652807 2025] [security2:error] [pid 2422:tid 2422] [client 104.207.60.12:60459] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.newhealthwaysaust.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.newhealthwaysaust.net"] [uri "/s3cmd.ini"] [unique_id "aRKwiag5AvDtPz4K1zQH1wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack