Anonymous
2026-02-09 21:56:32
(3 months ago)
104.207.33.77 - - [09/Feb/2026:21:56:15 +0000] "GET /api/.git/config HTTP/1.1" 302 645 "-" "Mozilla/ ...
show more
104.207.33.77 - - [09/Feb/2026:21:56:15 +0000] "GET /api/.git/config HTTP/1.1" 302 645 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:39:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:38:58.023044 2026] [security2:error] [pid 1494384:tid 1494384] [client 104.207.33.77:59295] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garon.us"] [uri "/wp/.git/config"] [unique_id "aYpT8oiu7vcXwqeXQCzbSAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 18:53:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 13:53:46.060013 2026] [security2:error] [pid 26616:tid 26616] [client 104.207.33.77:25899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fxztrader.com"] [uri "/v2/.git/config"] [unique_id "aYotOmSA3p77alh1686B6gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 11:27:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 06:27:10.894885 2026] [security2:error] [pid 12390:tid 12390] [client 104.207.33.77:45619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galengetting.com"] [uri "/dev/.git/config"] [unique_id "aYnEjo9I0z61fDSGr-tztAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 06:14:33
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 01:14:24.191354 2026] [security2:error] [pid 9168:tid 9187] [client 104.207.33.77:47025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furball.co.uk"] [uri "/admin/.git/config"] [unique_id "aYl7QOeaTQ9a1qvEhHBJLwAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 04:18:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 23:18:35.255095 2026] [security2:error] [pid 21065:tid 21065] [client 104.207.33.77:51343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fullbladderclub.com"] [uri "/api/.env"] [unique_id "aYlgG_0VHXI_jyDpe2IK-gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 03:16:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 22:16:22.854489 2026] [security2:error] [pid 4725:tid 4725] [client 104.207.33.77:25523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuegolounge813.com"] [uri "/api/.env"] [unique_id "aYlRhjY44jAOAcn7RSY5mwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:56
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-11-28 00:15:28
(6 months ago)
Attempted brute force login to web vpn 24 time(s); last attempt for 2025.11.28 is noted in report ti ...
show more
Attempted brute force login to web vpn 24 time(s); last attempt for 2025.11.28 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-11-13 23:48:36
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-11-11 10:30:52
(6 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.11.11 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.11.11 is noted in report timestamp
show less
Hacking
Brute-Force
๐ณ๐ฑ
enpepet
2025-11-07 07:23:42
(6 months ago)
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHT ...
show more
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 URL:/.env
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-06 23:19:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 18:19:18.261162 2025] [security2:error] [pid 15368:tid 15368] [client 104.207.33.77:54787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitalitywebb.com"] [uri "/.env"] [unique_id "aQ0s9v54MjtFamqTo2WHwAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
wil.com
2025-10-29 02:34:35
(7 months ago)
GlobalProtect login attempts with user jcatoe.
VPN IP
Brute-Force
Anonymous
2025-10-18 08:35:15
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force