π±π»
garmtech.com
2026-03-23 20:29:06
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 22-29.104.207.33.10.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 22-29.104.207.33.10.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
πͺπΈ
librebit
2026-03-21 04:31:52
(2 months ago)
Brute force
Brute-Force
πΊπΈ
TPI-Abuse
2026-02-12 06:30:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 01:30:10.555238 2026] [security2:error] [pid 816361:tid 816361] [client 104.207.33.10:18151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arttechnology.net"] [uri "/api/.env"] [unique_id "aY1zcr0Gvj56fjVqQmmAWgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 15:30:58
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 10:30:51.939023 2026] [security2:error] [pid 15613:tid 15613] [client 104.207.33.10:22569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestattorneys.com"] [uri "/.env.production"] [unique_id "aYtPKxK6c4RvozKa5rCXVgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 06:29:04
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 01:28:58.655726 2026] [security2:error] [pid 4110:tid 4110] [client 104.207.33.10:63643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konahawaiirealty.com"] [uri "/v2/.git/config"] [unique_id "aYrQKrk_eAKjKiPmzX7tFQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 04:40:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:40:13.389604 2026] [security2:error] [pid 10179:tid 10179] [client 104.207.33.10:29003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idatex.us"] [uri "/api/.env"] [unique_id "aYq2rc3kcvGFnkagTG_5iwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 03:03:40
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:03:34.745293 2026] [security2:error] [pid 10268:tid 10268] [client 104.207.33.10:29493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madrigalscripts.com"] [uri "/api/.env"] [unique_id "aYqgBsYV2eQfwjHXwShLXAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 02:35:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:35:01.764418 2026] [security2:error] [pid 4086:tid 4086] [client 104.207.33.10:9481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hyps.net"] [uri "/backup/.git/config"] [unique_id "aYqZVTiX-nwrrZsEPrlRvQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 23:45:07
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:45:04.432675 2026] [security2:error] [pid 9793:tid 9793] [client 104.207.33.10:48313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kemela.com"] [uri "/.git/config"] [unique_id "aYpxgGLthAPem9MMOdt-VwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 23:08:45
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:08:41.318841 2026] [security2:error] [pid 16856:tid 16856] [client 104.207.33.10:46137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hpepaper.com"] [uri "/api/.git/config"] [unique_id "aYpo-afy3u5EmK92T_sJAwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 22:15:26
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:15:16.545371 2026] [security2:error] [pid 6158:tid 6158] [client 104.207.33.10:36771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotjive.com"] [uri "/.env.save"] [unique_id "aYpcdLjaquyJz9EWwSvOQgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xserverx.ru
2026-02-09 21:16:28
(4 months ago)
Honeypot triggered:
IP: 104.207.33.10
Request to: https://horny-pot.ru/wp/.git/config
Method: GET
Ho ...
show more
Honeypot triggered:
IP: 104.207.33.10
Request to: https://horny-pot.ru/wp/.git/config
Method: GET
Host: horny-pot.ru
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
Referer: Direct
Country: US
ASN: Unknown
Triggered rules: (\.git/|\.gitignore|\.git/config), /\.git
Timestamp: 2026-02-09T21:16:27.997Z
show less
Hacking
Bad Web Bot
Web App Attack
π§π·
SOC Blue Team
2026-01-16 17:48:24
(4 months ago)
Tatic: TA0006 | Technique: T1110 | Source: TAP | Country Destination: BR
Brute-Force
πΊπΈ
myagent.site
2026-01-13 11:55:47
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
Anonymous
2025-12-12 19:14:10
(5 months ago)
botnet
DDoS Attack