๐บ๐ธ
TPI-Abuse
2026-02-11 20:47:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 15:46:58.094618 2026] [security2:error] [pid 30566:tid 30566] [client 104.207.48.168:52717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arcticwarriors.org"] [uri "/app/.git/config"] [unique_id "aYzqwrYA8kc9PvvoO87PkQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 23:00:24
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐ท๐บ
loveprod
2026-02-10 15:01:03
(3 months ago)
104.207.48.168 - - [10/Feb/2026:18:01:03 +0300] "GET /admin/.env HTTP/1.1" 301 352 "-" "Mozilla/5.0 ...
show more
104.207.48.168 - - [10/Feb/2026:18:01:03 +0300] "GET /admin/.env HTTP/1.1" 301 352 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.207.48.168 - - [10/Feb/2026:18:01:03 +0300] "GET http://0e39.top/.git/config HTTP/1.1" 301 355 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-10 06:28:55
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 01:28:52.066643 2026] [security2:error] [pid 25987:tid 25987] [client 104.207.48.168:16285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konar-steenberg.com"] [uri "/config/.env"] [unique_id "aYrQJFuo9GSLRvz_61eCcgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-02-10 06:06:28
(3 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /api/.git/con ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /api/.git/config
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:03:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:03:35.677003 2026] [security2:error] [pid 10452:tid 10452] [client 104.207.48.168:44581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madrigalscripts.com"] [uri "/admin/.env"] [unique_id "aYqgB43KTp7RbVPzewa0fwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:50:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:50:31.854631 2026] [security2:error] [pid 28798:tid 28798] [client 104.207.48.168:18635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keystonestandard.com"] [uri "/site/.git/config"] [unique_id "aYqA18MiG1C5Go4yyC9pPgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:32:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:32:30.276314 2026] [security2:error] [pid 11732:tid 11732] [client 104.207.48.168:30263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevamra.com"] [uri "/.env.local"] [unique_id "aYp8nvtDh4ejPvxpCWJ3pQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:11:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:10:37.411652 2026] [security2:error] [pid 31834:tid 31834] [client 104.207.48.168:61449] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hppagewidetampa.com"] [uri "/backend/.env"] [unique_id "aYppbbdvBznibL7rsj_aSAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:48:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:48:27.595982 2026] [security2:error] [pid 2597:tid 2597] [client 104.207.48.168:45241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houstoun.me"] [uri "/v2/.git/config"] [unique_id "aYpkO6zjRfE7SRpdfULxfQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:19:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:19:48.221021 2026] [security2:error] [pid 22654:tid 22654] [client 104.207.48.168:17145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homewaterproofing.com"] [uri "/config/.env"] [unique_id "aYpBZOO_8kM_IaYAcIdFCgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-01-30 05:09:38
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2026-01-05 11:39:16
(5 months ago)
Infected user bad webscan
Exploited Host
๐ซ๐ท
applemooz
2025-11-01 12:04:43
(7 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ฆ๐บ
AWW-Admin
2025-10-29 13:17:32
(7 months ago)
(wordpress) Failed wordpress login from 104.207.48.168 (BR/Brazil/-)
Brute-Force