Anonymous
2026-05-19 08:58:33
(4 weeks ago)
Fail2ban filtered
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 08:24:13
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 03:24:07.242624 2026] [security2:error] [pid 7688:tid 7688] [client 104.207.48.159:41823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lacycustombuilt.com"] [uri "/admin/.env"] [unique_id "aY7fpwlR06h_Io7A3mP_uwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 07:39:40
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 02:39:36.326610 2026] [security2:error] [pid 23231:tid 23354] [client 104.207.48.159:48945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwainet.com"] [uri "/.env.staging"] [unique_id "aY7VON9xpba3iFiyjSbUigAAAgY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 05:12:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 00:12:56.032125 2026] [security2:error] [pid 26453:tid 26453] [client 104.207.48.159:16157] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kmp.net"] [uri "/backup/.git/config"] [unique_id "aY6y2J7po-wVJP66BQhnCQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 03:19:04
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 22:18:59.038402 2026] [security2:error] [pid 25680:tid 25680] [client 104.207.48.159:24893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kh6jim.com"] [uri "/wp/.git/config"] [unique_id "aY6YIwFeeO23SQ8Px8kfMQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 02:13:02
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 21:12:55.619747 2026] [security2:error] [pid 4592:tid 4592] [client 104.207.48.159:63051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keeftone.com"] [uri "/backend/.env"] [unique_id "aY6Ip5jzTF3QO3Ytc0s-RQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-13 01:26:10
(4 months ago)
Blocking for trying to access an exploit file: /dev/.git/config
Hacking
๐ณ๐ฑ
BlueWire Hosting
2026-02-13 01:23:10
(4 months ago)
Probing websites for vulnerabilities
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-12 23:00:57
(4 months ago)
Auto-ban: >3000 req/min op 2026-02-12
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-12 19:06:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 14:05:54.198918 2026] [security2:error] [pid 24017:tid 24017] [client 104.207.48.159:19841] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "farmers123.com"] [uri "/.git/config"] [unique_id "aY4kkj_JuLs8M1K0JpRlUAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Jordy
2026-02-12 19:03:29
(4 months ago)
12/Feb/2026:19:59:59.428022 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
12/Feb/2026:19:59:59.428022 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 104.207.48.159] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "familievandemaat.nl"] [uri "/.git/config"] [unique_id "aY4jLwY7IhQxw-Uk38snIgAAAAI"]
12/Feb/2026:19:59:59.428022 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 104.207.48.159] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 22:07:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 17:07:27.487950 2026] [security2:error] [pid 12630:tid 12630] [client 104.207.48.159:50383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cozydesignae.com"] [uri "/app/.git/config"] [unique_id "aYz9n3awHHFXB8PQ9ZsPygAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-02-11 07:12:29
(4 months ago)
Web attack from 104.207.48.159
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 05:43:09
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 00:43:02.729196 2026] [security2:error] [pid 30537:tid 30537] [client 104.207.48.159:38899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "corstratinc.com"] [uri "/wp/.git/config"] [unique_id "aYwW5vEt_V7zWAJt6Y2dQQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 21:48:04
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 16:47:58.883523 2026] [security2:error] [pid 11746:tid 11746] [client 104.207.48.159:21955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conversationtalentnetwork.com"] [uri "/.env.save"] [unique_id "aYunjg9oEvo2BxnepMWaVgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack