๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2026-02-09 21:56:22
(4 months ago)
104.207.50.203 - - [09/Feb/2026:21:56:05 +0000] "GET /site/.git/config HTTP/1.1" 404 6185 "-" "Mozil ...
show more
104.207.50.203 - - [09/Feb/2026:21:56:05 +0000] "GET /site/.git/config HTTP/1.1" 404 6185 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:44:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:44:07.027288 2026] [security2:error] [pid 6706:tid 6706] [client 104.207.50.203:21951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garthp.com"] [uri "/.env.staging"] [unique_id "aYpVJ_p1RyB1ulbvg-0jcgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:10:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:10:05.709828 2026] [security2:error] [pid 7466:tid 7466] [client 104.207.50.203:40977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gapanda.com"] [uri "/admin/.env"] [unique_id "aYpNLa3si8wACyNLzLEdigAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 19:42:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 14:42:08.252744 2026] [security2:error] [pid 25848:tid 25848] [client 104.207.50.203:10589] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gadgeteer.net"] [uri "/frontend/.env"] [unique_id "aYo4kEYD3jP6r0DTvlV0kwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 11:27:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 06:27:30.391983 2026] [security2:error] [pid 174439:tid 174563] [client 104.207.50.203:38915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galeria.cl"] [uri "/.env.production"] [unique_id "aYnEorBStXOODiSAdTvsJgAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
barbarella
2026-02-09 10:07:20
(4 months ago)
hacking attempt of version control system (GET /new/.git/config)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 05:35:09
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 00:34:58.542696 2026] [security2:error] [pid 3353:tid 3359] [client 104.207.50.203:59413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "funerariafernandez.net"] [uri "/frontend/.env"] [unique_id "aYlyAv1fhnrDJGLVNOZBdgAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-08 21:27:03
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 16:26:56.522415 2026] [security2:error] [pid 20586:tid 20586] [client 104.207.50.203:40043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fusteriafontane.com"] [uri "/.svn/wc.db"] [unique_id "aYj_oCPU3cIU-R4cdNGtEgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-12-22 04:51:28
(5 months ago)
WP Login Scan Activities
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-03 05:59:29
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.50.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 03 00:59:24.393817 2025] [security2:error] [pid 15047:tid 15047] [client 104.207.50.203:48207] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cruisingforsex.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cruisingforsex.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aS_RvDrj11FQ0whZ12MhzQAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-11-29 22:10:02
(6 months ago)
WP Login Scan Activities
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-11-28 01:09:45
(6 months ago)
WP Login Scan Activities
Web App Attack
๐ช๐ธ
el-brujo
2025-11-21 11:32:50
(6 months ago)
[Fri Nov 21 12:32:49.085672 2025] [proxy_fcgi:error] [pid 1291806:tid 1291860] [remote 104.207.50.20 ...
show more
[Fri Nov 21 12:32:49.085672 2025] [proxy_fcgi:error] [pid 1291806:tid 1291860] [remote 104.207.50.203:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Fri Nov 21 12:32:50.206498 2025] [proxy_fcgi:error] [pid 1291827:tid 1292166] [remote 104.207.50.203:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-11-19 07:07:07
(6 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host