๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2026-02-25 07:56:55
(3 months ago)
"POST /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 19:48:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 14:48:02.013214 2026] [security2:error] [pid 569322:tid 569322] [client 104.207.45.41:10305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archief.org"] [uri "/.env.staging"] [unique_id "aYzc8kHG7bNiKIpx6oMw5AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 23:00:55
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-10 04:09:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:09:09.400797 2026] [security2:error] [pid 2815:tid 2815] [client 104.207.45.41:45801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iceofparadise.com"] [uri "/admin/.git/config"] [unique_id "aYqvZc-pE_zKkF3JGCSZngAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-02-10 03:51:49
(3 months ago)
104.207.45.41 - - [09/Feb/2026:20:51:49 -0700] "GET /test/.git/config HTTP/1.1" 404 8556 "-" "Mozill ...
show more
104.207.45.41 - - [09/Feb/2026:20:51:49 -0700] "GET /test/.git/config HTTP/1.1" 404 8556 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:55:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:55:45.970187 2026] [security2:error] [pid 2012:tid 2012] [client 104.207.45.41:61581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingfishbets.com"] [uri "/.env.local"] [unique_id "aYqeMdbsY7U1Zb8jErPByQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:50:30
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:50:25.178049 2026] [security2:error] [pid 8221:tid 8223] [client 104.207.45.41:31803] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humaehealth.com"] [uri "/frontend/.env"] [unique_id "aYqA0cfitxoJcbezxZk5dQAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:07:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:06:54.778718 2026] [security2:error] [pid 1592:tid 1592] [client 104.207.45.41:53805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathynash.com"] [uri "/admin/.git/config"] [unique_id "aYpafmCyDHz77FNRu_kpzAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 22:05:38
(3 months ago)
Blocking for trying to access an exploit file: /v2/.git/config
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 20:28:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:28:45.180901 2026] [security2:error] [pid 19337:tid 19350] [client 104.207.45.41:48763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kandooo.com"] [uri "/frontend/.env"] [unique_id "aYpDfR9XhWz9IoldCWnd9wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:08:38
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:08:25.053055 2026] [security2:error] [pid 17479:tid 17479] [client 104.207.45.41:23753] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homeschoolwv.com"] [uri "/dev/.git/config"] [unique_id "aYo-uRmwUzpykMYCLfYOIQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 19:45:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 14:45:31.169453 2026] [security2:error] [pid 26324:tid 26324] [client 104.207.45.41:58333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homebuyerpros.com"] [uri "/test/.git/config"] [unique_id "aYo5W-faYQYdVyEQvJ5tTgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-22 18:50:52
(5 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-12-09 11:24:15
(5 months ago)
botnet
DDoS Attack