๐ช๐ธ
librebit
2026-05-17 08:21:04
(4 weeks ago)
Brute force
Brute-Force
Anonymous
2026-05-12 17:58:35
(1 month ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
๐ธ๐ช
Juha Jurvanen
2026-05-10 22:10:36
(1 month ago)
RdpGuard detected brute-force attempt on RD-WEB
Brute-Force
๐ซ๐ท
bigorre.org
2026-03-14 15:59:19
(3 months ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐บ๐ธ
mnsf
2026-02-15 13:05:06
(4 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 11:51:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:51:12.708726 2026] [security2:error] [pid 8652:tid 8652] [client 104.207.33.167:47519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thunderbirdchimes.com"] [uri "/.env"] [unique_id "aZGzMJrV_ez3a5iUj6uu3gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-15 11:50:52
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐จ๐ญ
Origon
2026-02-15 11:35:48
(4 months ago)
http-sensitive-files - IP: 104.207.33.167 - time="2026-02-15T12:35:48+01:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 104.207.33.167 - time="2026-02-15T12:35:48+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 104.207.33.167 (US/200373) : 4h ban on Ip 104.207.33.167" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 06:05:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:05:07.913189 2026] [security2:error] [pid 877108:tid 877108] [client 104.207.33.167:37681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sykesclan.com"] [uri "/api/.env"] [unique_id "aZFiE0yQqZBZcr1vz_DNZQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:53:31
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:53:26.514226 2026] [security2:error] [pid 6589:tid 6589] [client 104.207.33.167:32121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suffolksystems.com"] [uri "/.git/config"] [unique_id "aZFRRt-4UOpjUynpE8ECNwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:14:02
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:13:54.506202 2026] [security2:error] [pid 24955:tid 24955] [client 104.207.33.167:63467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stpetersplayers.co.uk"] [uri "/backend/.env"] [unique_id "aZFIAvrhZhvzsL9gxjT5wgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:52:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:52:05.568397 2026] [security2:error] [pid 27789:tid 27789] [client 104.207.33.167:39309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "steveyett.com"] [uri "/test/.git/config"] [unique_id "aZFC5Rcr8J-rLzWMvDzEWwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-02-15 03:36:45
(4 months ago)
104.207.33.167 - - [15/Feb/2026:04:36:45 +0100] "GET /admin/.env HTTP/1.1" 404 3771 "-" "Mozilla/5.0 ...
show more
104.207.33.167 - - [15/Feb/2026:04:36:45 +0100] "GET /admin/.env HTTP/1.1" 404 3771 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.207.33.167 - - [15/Feb/2026:04:36:45 +0100] "GET /.env.save HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-02-15 03:15:57
(4 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 02:53:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:53:30.870492 2026] [security2:error] [pid 16971:tid 16971] [client 104.207.33.167:28259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nancybarrera.com"] [uri "/config/.env"] [unique_id "aZE1KmO885lhDf_9h-M8XgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack