π΅π±
dcnet
2026-03-08 00:00:00
(3 months ago)
SSL VPN brute force credential stuffing on FortiGate 100F - unknown user login attempts
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2026-02-12 08:45:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 03:45:23.122931 2026] [security2:error] [pid 4350:tid 4350] [client 104.207.62.33:23183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aschmidtconsulting.com"] [uri "/backup/.git/config"] [unique_id "aY2TI7YTzhKGGsKEHwvMkwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-11 21:14:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 16:14:04.731701 2026] [security2:error] [pid 19598:tid 19598] [client 104.207.62.33:20901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "areafinancieratf.com"] [uri "/api/.git/config"] [unique_id "aYzxHGIKvrghPvn-E1uaAwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-11 16:54:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 11:54:43.564009 2026] [security2:error] [pid 19726:tid 19726] [client 104.207.62.33:60949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aquanauticsige.com"] [uri "/backup/.git/config"] [unique_id "aYy0U5sB2SSWWUmM91mbSwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-02-10 23:00:54
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
πΊπΈ
TPI-Abuse
2026-02-10 03:08:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:08:12.835714 2026] [security2:error] [pid 25057:tid 25069] [client 104.207.62.33:59469] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madtruckerbill.com"] [uri "/backend/.env"] [unique_id "aYqhHNx5JYPt7AJhJMhWxgAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 02:33:27
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:33:24.449996 2026] [security2:error] [pid 11042:tid 11042] [client 104.207.62.33:47141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kindbyamber.com"] [uri "/.env.save"] [unique_id "aYqY9B_b5nSXJrUojDD0JQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-02-09 23:37:18
(4 months ago)
Blocking for trying to access an exploit file: /app/.env
Hacking
πΊπΈ
TPI-Abuse
2026-02-09 23:35:26
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:35:23.105793 2026] [security2:error] [pid 11420:tid 11420] [client 104.207.62.33:46805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kellermoving.com"] [uri "/new/.git/config"] [unique_id "aYpvO6HaNQlcw7UiD1HexQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-16 14:36:26
(7 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-07 09:21:28
(1 year ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-06 10:42:48
(1 year ago)
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.04.06 is noted in report tim ...
show more
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.04.06 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-05 21:48:25
(1 year ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.05 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-04 20:53:40
(1 year ago)
Attempted brute force login to web vpn 10 time(s); last attempt for 2025.04.04 is noted in report ti ...
show more
Attempted brute force login to web vpn 10 time(s); last attempt for 2025.04.04 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-02 23:10:13
(1 year ago)
Attempted brute force login to web vpn 9 time(s); last attempt for 2025.04.02 is noted in report tim ...
show more
Attempted brute force login to web vpn 9 time(s); last attempt for 2025.04.02 is noted in report timestamp
show less
Hacking
Brute-Force