๐ฑ๐ป
garmtech.com
2026-02-11 21:16:11
(3 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-02-11 21:04:33
(3 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-11 04:52:45
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /dev/.git/config (Rule ID: 930130) - Restricted File Access Attempt
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 16:10:54
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 11:10:50.976566 2026] [security2:error] [pid 21045:tid 21071] [client 104.207.42.75:21875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "12am.us"] [uri "/v2/.git/config"] [unique_id "aYtYikbhlAcrdkcO_sPbzwAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 04:29:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:29:40.007917 2026] [security2:error] [pid 1020:tid 1020] [client 104.207.42.75:19549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kleens-uk.com"] [uri "/.env.local"] [unique_id "aYq0NKyj_3SL9uOM8-sqHQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:53:09
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:53:01.500549 2026] [security2:error] [pid 4300:tid 4300] [client 104.207.42.75:60003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingdombuilderschurchmd.org"] [uri "/.git/config"] [unique_id "aYqdjeDEePGhYiZPc_SOFQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-13 00:39:33
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-12 23:04:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 18:04:09.394575 2026] [security2:error] [pid 19509:tid 19509] [client 104.207.42.75:37919] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arrowhead30.com"] [uri "/.git/HEAD"] [unique_id "aWV96elCwgpKf7YoRclhOgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 09:28:18
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 04:28:13.231513 2025] [security2:error] [pid 1455178:tid 1455178] [client 104.207.42.75:10593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armadillosigns.com"] [uri "/.svn/wc.db"] [unique_id "aVJJrXdvGRqFUz8k5LtINQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 09:05:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 04:05:09.227212 2025] [security2:error] [pid 23747:tid 23747] [client 104.207.42.75:45117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kennythompson.com"] [uri "/.env"] [unique_id "aVJERdC1t9CDS1fGmX4fZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:50:07
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.42.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:50:00.705536 2025] [security2:error] [pid 1235:tid 1235] [client 104.207.42.75:56085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rokket.com"] [uri "/.git/HEAD"] [unique_id "aVIIeHIQXcRHh1AFkF9xPQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-23 11:24:10
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
Anonymous
2025-11-14 13:19:04
(6 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2025-11-14 04:12:59
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2025-11-13 05:08:29
(6 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack