Anonymous
2026-06-09 12:59:38
(2 weeks ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ณ๐ฑ
jjnxpct
2026-02-16 04:54:54
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /api/.env (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .env found within REQUEST_FILENAME: /api/.env]
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-02-15 12:11:41
(4 months ago)
Web vulnerability probing: /admin/.env
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-02-15 10:56:39
(4 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.207.51.117 (GB/United Kingdom/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-02-15 06:59:29
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:59:23.048188 2026] [security2:error] [pid 23620:tid 23620] [client 104.207.51.117:23103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psicotanato.com"] [uri "/admin/.git/config"] [unique_id "aZFuy9FH-QK0PKwx8QACSwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 05:35:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:35:07.266870 2026] [security2:error] [pid 22199:tid 22228] [client 104.207.51.117:47725] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "priyom.us"] [uri "/backend/.env"] [unique_id "aZFbC76k6LPKjSLyJxBxGAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:21:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:21:18.162355 2026] [security2:error] [pid 2458653:tid 2458653] [client 104.207.51.117:13713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samuelcurtis.com"] [uri "/wp/.git/config"] [unique_id "aZFJvuPanvcAVkcKU-ScwAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:58:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:58:06.517032 2026] [security2:error] [pid 31310:tid 31310] [client 104.207.51.117:54341] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notepromd.com"] [uri "/.env.staging"] [unique_id "aZFETjhKk-IopUttuCme3AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 02:41:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:41:29.359129 2026] [security2:error] [pid 2935:tid 2935] [client 104.207.51.117:48571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "plumpen.com"] [uri "/backup/.git/config"] [unique_id "aZEyWRDP-SspO9plC1--wwAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 02:16:21
(4 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.207.51.117 (GB/United Kingdom/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-02-15 02:14:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:14:29.037900 2026] [security2:error] [pid 22840:tid 22840] [client 104.207.51.117:54615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newmooncafe.com"] [uri "/.git/config"] [unique_id "aZEsBVghZoxrAen69kX4RwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-02-15 01:50:50
(4 months ago)
26 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:45:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:45:12.512931 2026] [security2:error] [pid 6043:tid 6043] [client 104.207.51.117:10129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roselowry.com"] [uri "/test/.git/config"] [unique_id "aZElKHpN5CK8hT9G2v5yYQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:24:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.51.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:24:11.235831 2026] [security2:error] [pid 1100173:tid 1100173] [client 104.207.51.117:12401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nccb.org"] [uri "/app/.git/config"] [unique_id "aZEgO8J39x7Bp2iRZ2oDrwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-02-15 01:22:07
(4 months ago)
Multiple WAF Violations
Web App Attack