๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:11:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:11:08.063878 2026] [security2:error] [pid 2743610:tid 2743610] [client 104.207.42.212:9319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathiekate.com"] [uri "/.git/config"] [unique_id "aZZxPFbM08Rff4qo5eK18wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 01:28:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 20:27:54.909993 2026] [security2:error] [pid 17468:tid 17468] [client 104.207.42.212:50455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kanata.ws"] [uri "/frontend/.env"] [unique_id "aZZnGlin-S_LmcZgQuxPLwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 22:32:30
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 17:32:24.857159 2026] [security2:error] [pid 23277:tid 23277] [client 104.207.42.212:44047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uswebforce.com"] [uri "/config/.env"] [unique_id "aZY9-BIc1sglwifUrkB98gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 18:23:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:23:49.861510 2026] [security2:error] [pid 22788:tid 22788] [client 104.207.42.212:16553] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thetheaterathollywoodandvine.com"] [uri "/.env.production"] [unique_id "aZYDtWkS8SFvb1WSUOpLrwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-18 14:06:04
(3 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
๐ฉ๐ช
iNetWorker
2026-02-18 13:29:30
(3 months ago)
trolling for resource vulnerabilities
Web App Attack
๐จ๐ญ
Origon
2026-02-18 13:26:49
(3 months ago)
http-sensitive-files - IP: 104.207.42.212 - time="2026-02-18T14:26:49+01:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 104.207.42.212 - time="2026-02-18T14:26:49+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 104.207.42.212 (US/200373) : 4h ban on Ip 104.207.42.212" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 13:20:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:20:04.665472 2026] [security2:error] [pid 31514:tid 31514] [client 104.207.42.212:32967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "willmarksynthetics.com"] [uri "/frontend/.env"] [unique_id "aZW8hLDj3-yhguXn3f7SdQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:02:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:02:45.440246 2026] [security2:error] [pid 1183683:tid 1183683] [client 104.207.42.212:53379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waterarchitecture.com"] [uri "/app/.env"] [unique_id "aZWqZZ1zWLR4WWL6GgglfQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-10 10:22:54
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-29 16:28:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 11:28:41.593365 2025] [security2:error] [pid 24944:tid 24944] [client 104.207.42.212:59367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fabwestmfg.com"] [uri "/.git/config"] [unique_id "aSsfOS322Z0PtiukEvFEXgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 21:42:28
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-29 10:28:59
(7 months ago)
GlobalProtect login attempts with user cynthialawrence.
VPN IP
Brute-Force
๐จ๐ฆ
wil.com
2025-10-28 22:14:48
(7 months ago)
GlobalProtect login attempts with user andrewboykin.
VPN IP
Brute-Force