๐ฉ๐ช
4server
2026-04-21 11:21:45
(1 month ago)
[TueApr2113:21:40.0925112026][security2:error][pid3025358:tid3025369][client104.207.46.96:0]ModSecur ...
show more
[TueApr2113:21:40.0925112026][security2:error][pid3025358:tid3025369][client104.207.46.96:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"bestrestmaterassi.ch\"][uri\"/database.sql\"][unique_id\"aeddxBhJ3UcICK2T19yPYQAAAQg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-12 22:59:20
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-12
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-12 02:10:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 21:10:49.757078 2026] [security2:error] [pid 1217:tid 1217] [client 104.207.46.96:55469] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arresteddevelopmentinsight.org"] [uri "/app/.git/config"] [unique_id "aY02qa7MqYc1_XhnDlrIAAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-02-11 21:05:27
(3 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 16:53:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 11:53:27.912429 2026] [security2:error] [pid 19019:tid 19019] [client 104.207.46.96:60957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aquanauticsige.com"] [uri "/config/.env"] [unique_id "aYy0ByxIx3GKn2eJP76A1wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 15:55:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 10:55:51.724455 2026] [security2:error] [pid 17051:tid 17051] [client 104.207.46.96:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antitribu.com"] [uri "/backup/.git/config"] [unique_id "aYtVB2ZP8dFcO_fdurgApwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:12:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:12:21.007992 2026] [security2:error] [pid 24206:tid 24206] [client 104.207.46.96:18827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinnairdenterprisesllc.com"] [uri "/.git/config"] [unique_id "aYqiFd2vPmX7hR4FxmRJjAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 01:57:26
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 20:57:22.658258 2026] [security2:error] [pid 26580:tid 26580] [client 104.207.46.96:54233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madbanana.com"] [uri "/frontend/.env"] [unique_id "aYqQgiSAlT7uXQjMk_CD5QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 01:36:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 20:36:54.906965 2026] [security2:error] [pid 1326163:tid 1326163] [client 104.207.46.96:14105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "khurley.org"] [uri "/config/.env"] [unique_id "aYqLtuk3UvLHC8pdmQxC6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:23:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:23:44.271573 2026] [security2:error] [pid 19471:tid 19471] [client 104.207.46.96:47879] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kavahawaii.com"] [uri "/api/.git/config"] [unique_id "aYpecODkHj1vzNWEPHrxpgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2026-01-08 03:46:06
(4 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User A ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User Agent: N/A - Timestamp: 1/8/2026 3:46 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2026-01-04 00:58:33
(5 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User A ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User Agent: N/A - Timestamp: 1/4/2026 12:58 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2025-12-22 16:50:25
(5 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-12-16 01:30:52
(5 months ago)
botnet
DDoS Attack
Anonymous
2025-11-14 08:20:30
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack