๐ฉ๐ช
LRob.fr
2026-06-09 03:31:05
(4 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-05-07 05:26:43
(1 month ago)
Form spam
Web Spam
Anonymous
2026-04-12 05:40:22
(2 months ago)
Attempt to scan vulnerabilities
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-19 05:34:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 00:34:47.327928 2026] [security2:error] [pid 17049:tid 17049] [client 104.207.38.196:13213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ktnwassociatesinc.com"] [uri "/config/.env"] [unique_id "aZag92NqSwsfkFLY5Y2TGQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 03:13:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:13:30.329051 2026] [security2:error] [pid 6651:tid 6661] [client 104.207.38.196:48751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.net"] [uri "/config/.env"] [unique_id "aZZ_2s9-numDMILcxkPiyQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-02-19 01:39:05
(3 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
conseilgouz
2026-02-18 23:26:09
(3 months ago)
vee-17 : Block hidden directories=>/.env.staging(/)
Hacking
Anonymous
2026-02-18 22:51:03
(3 months ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1, GET /dev/.git/config HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1, GET /dev/.git/config HTTP/1.1, GET /wp/.git/config HTTP/1.1, GET /test/.git/config HTTP/1.1, GET /admin/.git/config HTTP/1.1, GET /v2/.git/config HTTP/1.1, GET /config/.env HTTP/1.1, GET /.env.local HTTP/1.1, GET /app/.git/config HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 18:55:38
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:55:31.909301 2026] [security2:error] [pid 12845:tid 12845] [client 104.207.38.196:10757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tianabes.com"] [uri "/backend/.env"] [unique_id "aZYLIxX2yavOYagqESHP1QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-02-18 18:44:37
(3 months ago)
[18/Feb/2026:19:44:36.982063 +0100] aZYIlH_iSLsPgX3dOMsDTAAAAAk 104.207.38.196 37832 127.0.0.1 7081
...
show more
[18/Feb/2026:19:44:36.982063 +0100] aZYIlH_iSLsPgX3dOMsDTAAAAAk 104.207.38.196 37832 127.0.0.1 7081
[18/Feb/2026:19:44:37.181223 +0100] aZYIlZ8oxRl-4MKmRnWQegAAAAE 104.207.38.196 37848 127.0.0.1 7081
[18/Feb/2026:19:44:37.380283 +0100] aZYIlUOMibi9zoSMO17vQQAAAAA 104.207.38.196 37862 127.0.0.1 7081
...
show less
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-02-18 18:40:25
(3 months ago)
bad bot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-18 18:30:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:30:27.414858 2026] [security2:error] [pid 16444:tid 16444] [client 104.207.38.196:52119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thevenicecafe.com"] [uri "/test/.git/config"] [unique_id "aZYFQ3I7GQEL2F303w3PigAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-18 17:07:32
(3 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 13:34:16
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:34:09.769587 2026] [security2:error] [pid 2102729:tid 2102729] [client 104.207.38.196:51713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisewerks.com"] [uri "/backend/.env"] [unique_id "aZW_0TCN1CogZ89NcMfunAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-11 09:01:00
(4 months ago)
SMS pumping
DDoS Attack
VPN IP
Bad Web Bot
Web App Attack