๐บ๐ธ
drewf.ink
2026-09-04 11:58:48
(1 month ago)
[11:58] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[11:58] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
๐ฉ๐ช
BR-DACH
2026-08-30 03:35:06
(1 month ago)
Automated Block: HACK in URI: extractvalue
Brute-Force
Bad Web Bot
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(6 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 00:38:31
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 19:38:25.290249 2026] [security2:error] [pid 26340:tid 26340] [client 104.207.38.87:24345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10mostwantedfugitives.com"] [uri "/new/.git/config"] [unique_id "aY0hAc6tJPUOxm1KYMemSgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 16:13:16
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 11:13:12.908433 2026] [security2:error] [pid 29684:tid 29684] [client 104.207.38.87:17319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "holtzheimer.net"] [uri "/.env.save"] [unique_id "aYyqmPnBKgXyw3KxfLkowwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 23:00:07
(7 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-10 17:28:29
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 12:28:24.860479 2026] [security2:error] [pid 24450:tid 24450] [client 104.207.38.87:28855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anythingsoldworldwide.com"] [uri "/v2/.git/config"] [unique_id "aYtquGfHYYTPupFylMKLOAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 16:10:55
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 11:10:48.860864 2026] [security2:error] [pid 29672:tid 29685] [client 104.207.38.87:24161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "12am.com"] [uri "/.env.local"] [unique_id "aYtYiGqmJhIz38r7Ayr3mAAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 05:47:16
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:47:09.478325 2026] [security2:error] [pid 17216:tid 17216] [client 104.207.38.87:48601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mahoninginn.com"] [uri "/new/.git/config"] [unique_id "aYrGXcG-6-uDlkAIQPBCMQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 04:48:09
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:48:04.102405 2026] [security2:error] [pid 1164323:tid 1164340] [client 104.207.38.87:50189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magnetbay.com"] [uri "/api/.env"] [unique_id "aYq4hJu0XmnEVHvC_jK8-AAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:48:17
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:48:02.139228 2026] [security2:error] [pid 24114:tid 24114] [client 104.207.38.87:32289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keyspring-niseko.com"] [uri "/admin/.env"] [unique_id "aYqAQuDxd_NxFl512CwRZQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:46:12
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:46:07.447162 2026] [security2:error] [pid 20616:tid 20616] [client 104.207.38.87:30291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "htaautosales.com"] [uri "/.env.save"] [unique_id "aYpxv3plRkUIjIIGD3loEwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-08 11:48:36
(10 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:36:56
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:36:51.980390 2025] [security2:error] [pid 25255:tid 25255] [client 104.207.38.87:55885] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.therennas.com"] [uri "/.svn/wc.db"] [unique_id "aSUyY3aNOnHGazk0deJAJwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:12:46
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:12:42.876904 2025] [security2:error] [pid 1235:tid 1235] [client 104.207.38.87:60483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amychop.com"] [uri "/.git/HEAD"] [unique_id "aSUsukAvHX4aAkxYw6bZYAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack