๐ซ๐ท
MatStef132
2026-05-19 21:11:04
(2 weeks ago)
MatShield L7: blocked on mathost.eu (ua-quarantined)
Bad Web Bot
๐ณ๐ฑ
MatStef132
2026-05-19 20:59:02
(2 weeks ago)
MatShield L7: blocked on dstat.selify.io (click-id-direct-nav)
DDoS Attack
๐ซ๐ท
MatStef132
2026-05-14 21:32:37
(3 weeks ago)
[mathost.eu] ua-q
DDoS Attack
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-04-28 15:44:20
(1 month ago)
Cloudflare WAF: Request Path: /123456 Request Query: ?ref=LT2KAFLWC7b Host: elhacker.net userAgent: ...
show more
Cloudflare WAF: Request Path: /123456 Request Query: ?ref=LT2KAFLWC7b Host: elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.129 Safari/537.36 Action: block Source: ratelimit ASN Description: 3xK Tech GmbH Country: US Method: GET Timestamp: 2026-04-28T15:44:20Z ruleId: 11a71ad4659e48b29b5173e3bcc61b4a. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 05:29:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 00:29:06.113680 2026] [security2:error] [pid 7585:tid 7585] [client 104.207.34.59:45685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krystalsgiftshopandboutique.net"] [uri "/admin/.git/config"] [unique_id "aZafouZQ93o8P9sVSox7ewAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-02-19 04:04:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (US/United States/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 03:59:16
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:59:08.014251 2026] [security2:error] [pid 6903:tid 6903] [client 104.207.34.59:18285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirbysmw.com"] [uri "/config/.env"] [unique_id "aZaKjMtrYaybkEmpHo_o4QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 19:53:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 14:53:18.402349 2026] [security2:error] [pid 8256:tid 8262] [client 104.207.34.59:32601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "torreymanagement.com"] [uri "/frontend/.env"] [unique_id "aZYYrge0_k0zcavpyCeAVgAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 18:41:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:41:16.990134 2026] [security2:error] [pid 163076:tid 163076] [client 104.207.34.59:31675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thinkingepic.com"] [uri "/.env.local"] [unique_id "aZYHzLU8qDgzS8-jrIuAVgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:36:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:36:52.506307 2026] [security2:error] [pid 18346:tid 18346] [client 104.207.34.59:47715] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wedemandavote.com"] [uri "/api/.git/config"] [unique_id "aZWyZKOLkZL5UOLpj3tSJwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:06:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:06:01.852007 2026] [security2:error] [pid 21090:tid 21090] [client 104.207.34.59:43827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "watlab.com"] [uri "/admin/.git/config"] [unique_id "aZWrKfGgh7JfGA3FMqsDmwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:47:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:47:21.396522 2026] [security2:error] [pid 3529:tid 3529] [client 104.207.34.59:43307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wandcompany.com"] [uri "/.env.staging"] [unique_id "aZWmyUFtbjrx88LQRDhUrAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-13 05:43:28
(3 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 02:39:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 21:39:16.891473 2026] [security2:error] [pid 362028:tid 362028] [client 104.207.34.59:39615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsenaultartistmanagement.com"] [uri "/test/.git/config"] [unique_id "aY09VMNrSaVeCSwIecGbNgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 17:33:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 12:33:26.048047 2026] [security2:error] [pid 3580648:tid 3580662] [client 104.207.34.59:40975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aqutar.com"] [uri "/wp/.git/config"] [unique_id "aYy9ZvDPXScg2TydKCgnfwAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack