๐บ๐ธ
TPI-Abuse
2026-02-19 03:53:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:53:06.975969 2026] [security2:error] [pid 18572:tid 18572] [client 104.207.53.120:50585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingscruff.com"] [uri "/backend/.env"] [unique_id "aZaJItMU3rRYrEviAyKCHQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:45:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:44:53.442027 2026] [security2:error] [pid 9023:tid 9090] [client 104.207.53.120:14651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keetons.net"] [uri "/app/.env"] [unique_id "aZZ5JbuDdUSGKYJlbufkjQAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 00:06:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 19:06:10.730939 2026] [security2:error] [pid 1503:tid 1503] [client 104.207.53.120:53033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "visitbyblos.com"] [uri "/backup/.git/config"] [unique_id "aZZT8pQVTWBYxxhbQ5hPTwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-02-18 18:31:59
(3 months ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-02-18 13:19:43
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:19:39.848956 2026] [security2:error] [pid 1270464:tid 1270464] [client 104.207.53.120:62121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "williamfitzsimmons.com"] [uri "/test/.git/config"] [unique_id "aZW8a2oOJpRsoue3lVYkMwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:25:16
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:25:12.529054 2026] [security2:error] [pid 28383:tid 28383] [client 104.207.53.120:59861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdryer.com"] [uri "/app/.env"] [unique_id "aZWvqFheTO0DTPPbToRQYwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-02-18 12:04:24
(3 months ago)
Try to access /.aws/credentials
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:01:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:01:29.376442 2026] [security2:error] [pid 27772:tid 27772] [client 104.207.53.120:62229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wastetrack.io"] [uri "/api/.git/config"] [unique_id "aZWqGeZ_epwQNg5XCUme7AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-01-03 14:39:19
(5 months ago)
Web App Attack
Web App Attack
๐ง๐ช
cmbplf
2025-12-13 13:59:16
(6 months ago)
9.200 POST requests in 1 hour (1w4d21h)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-25 06:18:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:18:38.511769 2025] [security2:error] [pid 19051:tid 19051] [client 104.207.53.120:25107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.keymarketmedia.com"] [uri "/.svn/wc.db"] [unique_id "aSVKPuNXOunavSWvdQLPZwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:42:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:42:22.842632 2025] [security2:error] [pid 6657:tid 6657] [client 104.207.53.120:47017] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bmbb1.com"] [uri "/.git/HEAD"] [unique_id "aSUzrhDeOSDRI6psIuyc_AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:04:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:04:21.121561 2025] [security2:error] [pid 23453:tid 23453] [client 104.207.53.120:44513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stamford.org"] [uri "/.git/HEAD"] [unique_id "aSUOpTI2TbqH9z3oJu_2UAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2025-10-27 10:28:22
(7 months ago)
Unauthorized connection to SSH port 22
Port Scan
Hacking
SSH
๐ฌ๐ง
adnscom.net
2025-10-27 09:44:32
(7 months ago)
IPS trigger: Brute force SSH scanning/attack
Brute-Force
SSH