๐ง๐ท
Halux
2026-05-13 10:57:42
(3 weeks ago)
104.207.37.172 Probing protected path or service
Web App Attack
Anonymous
2026-05-13 04:09:47
(3 weeks ago)
104.207.37.172 - - [13/May/2026:04:09:46 +0000] "GET http://owlandbee.co.uk/.env HTTP/1.1" 302 622 " ...
show more
104.207.37.172 - - [13/May/2026:04:09:46 +0000] "GET http://owlandbee.co.uk/.env HTTP/1.1" 302 622 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Edg/119.0.0.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 01:29:53
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 21:29:48.742634 2026] [security2:error] [pid 27432:tid 27432] [client 104.207.37.172:61755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "protexiasecure.com"] [uri "/.git/HEAD"] [unique_id "agPUDMvkPKdtUbzVqOcc1gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-12 19:28:49
(3 weeks ago)
Try to access /.svn/wc.db
Web App Attack
๐ฆ๐บ
oncord
2026-02-09 09:53:13
(3 months ago)
Form spam
Web Spam
๐บ๐ธ
oncord
2026-02-06 09:21:43
(4 months ago)
Form spam
Web Spam
๐ณ๐ฑ
pixelXp
2026-02-04 02:24:45
(4 months ago)
68.24 boyce.harney75 ฦฉgmaยกl pixelxp.com/contact
Web Spam
๐ฑ๐ป
garmtech.com
2026-01-12 12:22:18
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-22.104.207.37.172.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-22.104.207.37.172.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ต๐ฑ
sefinek.net
2025-12-29 10:56:40
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Linux i686; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฑ๐ป
garmtech.com
2025-12-16 10:10:36
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 12-10.104.207.37.172.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 12-10.104.207.37.172.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ญ๐บ
bcsaba
2025-12-14 07:34:44
(5 months ago)
Joomla spam
104.207.37.172 - - [14/Dec/2025:08:34:42 +0100] "GET /index.php?option=com_easyblog&view ...
show more
Joomla spam
104.207.37.172 - - [14/Dec/2025:08:34:42 +0100] "GET /index.php?option=com_easyblog&view=dashboard&layout=write HTTP/1.1" 404 789 "https://*REDACTED*" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 OPR/89.0.4447.51"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 19:13:11
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 14:13:07.982388 2025] [security2:error] [pid 19624:tid 19624] [client 104.207.37.172:47953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jsdavison.com"] [uri "/.env"] [unique_id "aTcjQyLet-_V0KQcWlCmwAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 18:45:01
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 13:44:56.462139 2025] [security2:error] [pid 15240:tid 15240] [client 104.207.37.172:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/.env"] [unique_id "aTccqGIm1T302H7mCvkbRAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 01:35:58
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 20:35:54.429866 2025] [security2:error] [pid 12085:tid 12085] [client 104.207.37.172:58481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realdoctorstories.com"] [uri "/.git/HEAD"] [unique_id "aTYrevavDfyTSVP4cRmLkgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 23:23:01
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 18:22:56.954735 2025] [security2:error] [pid 13300:tid 13300] [client 104.207.37.172:10909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "queenspridegrapes.nyc"] [uri "/.git/HEAD"] [unique_id "aTS60C8hjA8WGh7eRdJmLgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack