๐บ๐ธ
TPI-Abuse
2026-02-20 07:42:20
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 02:42:13.022586 2026] [security2:error] [pid 20127:tid 20127] [client 104.207.43.117:30169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honer.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honer.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZgQVcpoER-xKi1NzESGpAAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
windowsforum
2026-02-19 15:33:32
(3 months ago)
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, url, password_confirm, ...
show more
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, url, password_confirm, username=LadonnaHar
show less
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-11 23:50:57
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 18:50:49.629256 2026] [security2:error] [pid 4678:tid 4678] [client 104.207.43.117:42805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arklahomaflooring.com"] [uri "/test/.git/config"] [unique_id "aY0V2f3em6zkQSS04IdpSwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 20:45:27
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 15:45:22.110480 2026] [security2:error] [pid 28735:tid 28735] [client 104.207.43.117:42499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arcticwarriors.org"] [uri "/admin/.env"] [unique_id "aYzqYpLrIXJVJ-xpngs8fAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-02-10 22:27:57
(4 months ago)
Try to access /frontend/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:38:51
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:38:43.016350 2026] [security2:error] [pid 18403:tid 18403] [client 104.207.43.117:18437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ibcnu.com"] [uri "/new/.git/config"] [unique_id "aYqoQzVdPIp5R1S8Yb-7NQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:20:13
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:20:10.317503 2026] [security2:error] [pid 328:tid 328] [client 104.207.43.117:41745] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kipdollar.com"] [uri "/config/.env"] [unique_id "aYqj6jycYIVKQ281jmDTvAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Teufel100
2026-02-10 02:06:08
(4 months ago)
ModSecurity rejected a query'
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 01:14:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 20:14:00.078976 2026] [security2:error] [pid 13218:tid 13218] [client 104.207.43.117:41173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hunkworkout.com"] [uri "/backup/.git/config"] [unique_id "aYqGWHAI08l_Fv1EkemZzQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:06:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:06:12.690864 2026] [security2:error] [pid 1635552:tid 1635552] [client 104.207.43.117:59149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentuckyminiaturehorsebreeders.org"] [uri "/new/.git/config"] [unique_id "aYp2dArN_-tkVbNft0XGlQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-02-09 21:29:07
(4 months ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:18:45
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:18:34.092677 2026] [security2:error] [pid 18228:tid 18228] [client 104.207.43.117:56461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horse7.com"] [uri "/admin/.env"] [unique_id "aYpPKtuy0B-FqZB_F1oAkgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 18:56:14
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 13:56:08.345705 2026] [security2:error] [pid 29348:tid 29348] [client 104.207.43.117:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernbroadcast.com"] [uri "/.svn/wc.db"] [unique_id "aV6sSMSxfzjCao4bFlW2VQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2025-12-31 04:47:49
(5 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .env found within REQUEST_FILENAME: /.env]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 06:22:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.43.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:22:49.462612 2025] [security2:error] [pid 5909:tid 5909] [client 104.207.43.117:43977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eagrant.com"] [uri "/.git/HEAD"] [unique_id "aVIeOXw__ykb-3K_PI7CQgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack