๐ช๐ธ
librebit
2026-08-26 16:21:06
(1 day ago)
Brute force
Brute-Force
๐ซ๐ท
Sklurk
2026-07-29 02:35:26
(4 weeks ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-07 17:26:03
(1 month ago)
Web App Attack
Web App Attack
๐บ๐ธ
koinkash.org
2026-05-23 01:39:52
(3 months ago)
They are fraudulent. Malicious threat actor requesting php file /wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 15:17:05
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 10:16:58.233785 2026] [security2:error] [pid 6798:tid 6798] [client 104.207.62.142:14639] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pcsyportatiles.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pcsyportatiles.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZh66kMBr7xOkbKga_0AAAAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 10:26:21
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 05:26:14.006450 2026] [security2:error] [pid 24198:tid 24198] [client 104.207.62.142:18241] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kmp.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kmp.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZg2xjgKHjJU6gCcK_yKkAAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-05 20:09:50
(7 months ago)
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
๐ง๐ช
madeit
2025-11-30 04:32:45
(8 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 10:11:46
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:11:42.224014 2025] [security2:error] [pid 2713242:tid 2713242] [client 104.207.62.142:23625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bokharienterprises.stbms.com"] [uri "/.svn/wc.db"] [unique_id "aSbSXnb4RfORYD-Oa4YlEgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:30:40
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:30:35.310252 2025] [security2:error] [pid 24541:tid 24541] [client 104.207.62.142:13665] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.smartstylehair.com"] [uri "/.env"] [unique_id "aSa6q_HfwlNvjZW92cQ5NgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 07:05:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 02:05:45.773370 2025] [security2:error] [pid 3599211:tid 3599216] [client 104.207.62.142:29279] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.craftcentre.iancaird.com"] [uri "/.svn/wc.db"] [unique_id "aSamySWBb6LubLi-gSEssQAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:45:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:45:20.978418 2025] [security2:error] [pid 16934:tid 16971] [client 104.207.62.142:43143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.seracon.com.ec"] [uri "/.svn/wc.db"] [unique_id "aSaT8BKESCEx-WKRVnsm4QAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-26 00:49:00
(9 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:38:47
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:38:40.111036 2025] [security2:error] [pid 31863:tid 31863] [client 104.207.62.142:46347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stenbot.com"] [uri "/.env"] [unique_id "aSZMEJtBibpyHLqDMm5IZAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-30 15:09:01
(9 months ago)
WordPress Brute Force
Brute-Force