๐บ๐ธ
TPI-Abuse
2026-02-11 20:49:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 15:49:43.278408 2026] [security2:error] [pid 898798:tid 898798] [client 104.207.48.199:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ard.global"] [uri "/admin/.env"] [unique_id "aYzrZ3BAPO2f8Sz6CmiolAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 22:59:42
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐ซ๐ฎ
000rosiu
2026-02-10 14:11:09
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 200373 (DREI-K-TECH-GMBH ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 200373 (DREI-K-TECH-GMBH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /frontend/.env
Timestamp: 2026-02-10T14:00:03Z
Ray ID: 9cbc216bcc56ddfa
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-10 05:47:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:47:43.440849 2026] [security2:error] [pid 11993:tid 11993] [client 104.207.48.199:23527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mahtani.org"] [uri "/.env.local"] [unique_id "aYrGf1T_qxawhPVrZylpfQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:47:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:47:23.929902 2026] [security2:error] [pid 2813:tid 2813] [client 104.207.48.199:20095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ken-parker.com"] [uri "/.env.production"] [unique_id "aYpyC0s77U-OHPoUtqGNOgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:53:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:53:09.523779 2026] [security2:error] [pid 23026:tid 23026] [client 104.207.48.199:26735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katabigrock.net"] [uri "/api/.env"] [unique_id "aYpXRa3qPLqLM7hzs41xJAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:59:45
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:59:39.204104 2026] [security2:error] [pid 30001:tid 30001] [client 104.207.48.199:28167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karakostasconstruction.com"] [uri "/.git/config"] [unique_id "aYpKu5EBUZXQ9P00REdtiQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:30:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:30:45.203835 2025] [security2:error] [pid 26746:tid 26746] [client 104.207.48.199:12509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comsew.com.au"] [uri "/.git/HEAD"] [unique_id "aSUGxZ1NFPmaV8H5jtgQTQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:09:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:09:49.766318 2025] [security2:error] [pid 14243:tid 14243] [client 104.207.48.199:56503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alohaarts.com"] [uri "/.env"] [unique_id "aSP2rYMp5RKUjGOokHlHhAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:29:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:28:58.134051 2025] [security2:error] [pid 9485:tid 9485] [client 104.207.48.199:18693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gogitzit.com"] [uri "/.svn/wc.db"] [unique_id "aSPtGoSecUtb7ZKcHIiMhQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-10 15:03:05
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.48.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 10 11:02:58.065079 2025] [security2:error] [pid 32633:tid 32633] [client 104.207.48.199:57181] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mitchellamazing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mitchellamazing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOkgIp_F2F0sXoQStfRUZQAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
cheatmaster.store
2025-06-03 07:27:38
(1 year ago)
Open proxy and SSH brute force activity detected from VPS logs
Open Proxy
Brute-Force
Anonymous
2025-04-06 22:56:22
(1 year ago)
Attempted brute force login to web vpn 7 time(s); last attempt for 2025.04.06 is noted in report tim ...
show more
Attempted brute force login to web vpn 7 time(s); last attempt for 2025.04.06 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-05 15:52:08
(1 year ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.04.05 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-04 08:43:44
(1 year ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.04 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.04 is noted in report timestamp
show less
Hacking
Brute-Force