๐บ๐ธ
mnsf
2026-02-19 05:05:17
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-02-19 04:23:06
(3 months ago)
Try to access /admin/.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 03:21:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:21:35.466511 2026] [security2:error] [pid 20635:tid 20635] [client 104.207.55.86:59211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keyspring-niseko.com"] [uri "/api/.git/config"] [unique_id "aZaBvz94IjBVyEFck5Xu6AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Swiptly
2026-02-19 03:05:27
(3 months ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:51:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:51:42.033154 2026] [security2:error] [pid 12708:tid 12708] [client 104.207.55.86:41501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kellermoving.com"] [uri "/test/.git/config"] [unique_id "aZZ6vqklmUl-7Ih9HRNZLQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 19:57:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 14:57:28.019479 2026] [security2:error] [pid 8256:tid 8275] [client 104.207.55.86:39667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "touficcorban.com"] [uri "/.env.local"] [unique_id "aZYZqAe0_k0zcavpyCeBlAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:35:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:34:56.683122 2026] [security2:error] [pid 23560:tid 23560] [client 104.207.55.86:24451] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weddingcapitalpartners.com"] [uri "/config/.env"] [unique_id "aZWx8KazBfEIjF_LjuSwbAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:09:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:09:44.493169 2026] [security2:error] [pid 4754:tid 4754] [client 104.207.55.86:40529] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waynejarvi.com"] [uri "/test/.git/config"] [unique_id "aZWsCGxVNpwkig7uFtLOEAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:53:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:53:14.206545 2026] [security2:error] [pid 804532:tid 804536] [client 104.207.55.86:64867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waqm.org"] [uri "/backup/.git/config"] [unique_id "aZWoKiVMIGSGO_bGgZA4nAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-20 16:44:11
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 11:43:58.740718 2026] [security2:error] [pid 23616:tid 23616] [client 104.207.55.86:45693] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.oualierealty.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.oualierealty.com"] [uri "/index.php"] [unique_id "aW-wzjqSzFrHb1vvYBE2kAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 17:02:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 12:02:25.806060 2025] [security2:error] [pid 8278:tid 8278] [client 104.207.55.86:13381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itibitico.com"] [uri "/.svn/wc.db"] [unique_id "aThWIWYjK4p7IjnWSeFLZgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 19:13:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 14:13:00.083186 2025] [security2:error] [pid 19627:tid 19627] [client 104.207.55.86:42735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acmedistributingllc.com"] [uri "/.git/HEAD"] [unique_id "aTcjPP03hmhBg_rXUio5LAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 09:50:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 04:50:19.211259 2025] [security2:error] [pid 24865:tid 24865] [client 104.207.55.86:14901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thelostfruit.com"] [uri "/.git/HEAD"] [unique_id "aTafW22E9Xom4_-OPGjD7QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-12-07 20:56:19
(6 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-05 17:32:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 12:32:06.503726 2025] [security2:error] [pid 30870:tid 30870] [client 104.207.55.86:23381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eurocs2.com"] [uri "/.git/HEAD"] [unique_id "aTMXFsEOPrYD5aoc6QwqgQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack