π¦πΊ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
π«π·
dynamix
2026-02-15 12:18:41
(3 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
kosada.com
2026-02-15 12:11:41
(3 months ago)
Web vulnerability probing: /admin/.env
Web App Attack
πΊπΈ
mnsf
2026-02-15 07:06:01
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
π©πͺ
big-cloud.nl
2026-02-15 06:46:10
(3 months ago)
Try to access /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 04:36:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:35:56.203306 2026] [security2:error] [pid 25351:tid 25351] [client 104.207.53.248:32659] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sangalgano.info"] [uri "/site/.git/config"] [unique_id "aZFNLN_yZ81sZ8n_Rx2P-QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 04:14:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:14:52.028025 2026] [security2:error] [pid 19794:tid 19794] [client 104.207.53.248:46105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pozzolan.org"] [uri "/app/.env"] [unique_id "aZFIPGKAy0vT6haK7RryOAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 03:44:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:44:54.814454 2026] [security2:error] [pid 30264:tid 30264] [client 104.207.53.248:50351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portcitybluessociety.com"] [uri "/.env.local"] [unique_id "aZFBNnbMZQyZFlNim43_uQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 02:41:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:41:47.091223 2026] [security2:error] [pid 6296:tid 6296] [client 104.207.53.248:9589] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pluscures.com"] [uri "/admin/.env"] [unique_id "aZEya5zBxI3FH1DjlGX8ZwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 02:23:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:23:32.789277 2026] [security2:error] [pid 250824:tid 250868] [client 104.207.53.248:33103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newyorkgazette.com"] [uri "/site/.git/config"] [unique_id "aZEuJLzgCarsQLWpGm1-HQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
Origon
2026-02-15 01:57:14
(3 months ago)
http-sensitive-files - IP: 104.207.53.248 - time="2026-02-15T02:57:14+01:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 104.207.53.248 - time="2026-02-15T02:57:14+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 104.207.53.248 (GB/200373) : 4h ban on Ip 104.207.53.248" module=db
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 01:51:55
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:51:46.127297 2026] [security2:error] [pid 18685:tid 18685] [client 104.207.53.248:13981] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pistone.us"] [uri "/.env.save"] [unique_id "aZEmstOGkwVO5uDRpslabwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 01:30:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:30:44.567499 2026] [security2:error] [pid 31986:tid 31986] [client 104.207.53.248:13257] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ronniescedarinn.com"] [uri "/dev/.git/config"] [unique_id "aZEhxA3KFr6AfIZgEfei2QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 01:14:38
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:14:34.234030 2026] [security2:error] [pid 1086206:tid 1086206] [client 104.207.53.248:25809] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rohrbachfamilyfarms.com"] [uri "/dev/.git/config"] [unique_id "aZEd-hTNoJmb_ix_CFQbaQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 00:48:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.53.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 19:48:39.141504 2026] [security2:error] [pid 662527:tid 662527] [client 104.207.53.248:57133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naomicotten.com"] [uri "/v2/.git/config"] [unique_id "aZEX50reaOi2QB77PM2eRgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack