๐จ๐ณ
ThreatBook.io
2025-11-27 02:26:47
(6 months ago)
ThreatBook Intelligence: http_proxy,Zombie more details on https://threatbook.io/ip/104.207.55.98
20 ...
show more
ThreatBook Intelligence: http_proxy,Zombie more details on https://threatbook.io/ip/104.207.55.98
2025-11-26 16:48:17 /.aws/credentials
2025-11-26 17:27:52 /.svn/wc.db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 06:08:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:08:51.102006 2025] [security2:error] [pid 9262:tid 9262] [client 104.207.55.98:30691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tomdaughertyorchestra.com"] [uri "/.env"] [unique_id "aSaZc7sSwc0V9bUSd7-4TQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 03:41:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 22:41:47.410224 2025] [security2:error] [pid 32007:tid 32029] [client 104.207.55.98:47625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.losersoftheyear.net"] [uri "/.git/HEAD"] [unique_id "aSZ2-4oXs7RvdIeQn_MragAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 02:23:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:23:16.927979 2025] [security2:error] [pid 1755:tid 1755] [client 104.207.55.98:50889] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keeftone.tech-servusa.com"] [uri "/.git/HEAD"] [unique_id "aSZklLrjPWdorCuYWEH_6QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:43:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:43:16.135221 2025] [security2:error] [pid 475:tid 475] [client 104.207.55.98:49643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.athletefirst.org"] [uri "/.env"] [unique_id "aSZNJI5M_77_BVydBOEbwwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:17:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:16:47.202804 2025] [security2:error] [pid 17628:tid 17628] [client 104.207.55.98:31581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gellertdealers.com"] [uri "/.env"] [unique_id "aSVJz2JjQzCStQfPsKnMSgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:53:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:53:11.252568 2025] [security2:error] [pid 3976:tid 3976] [client 104.207.55.98:38947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.michaelpmcgrath.com"] [uri "/.env"] [unique_id "aSU2N0nWQanUK1UGyorp_QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:22:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:22:33.031888 2025] [security2:error] [pid 27141:tid 27141] [client 104.207.55.98:27003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.peterjohnsonauthor.com"] [uri "/.svn/wc.db"] [unique_id "aSUvCXZ4y5A8ExvHvwnrmwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:38:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:38:32.899656 2025] [security2:error] [pid 30062:tid 30062] [client 104.207.55.98:15729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.civilwarzone.com"] [uri "/.env"] [unique_id "aSUkuG8QR0-DMyq0LyU_nQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:17:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:17:06.460387 2025] [security2:error] [pid 17023:tid 17070] [client 104.207.55.98:30151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.neotienda.com"] [uri "/.env"] [unique_id "aSUfsr1hG8E8_fObGRh65AAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:49:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:49:19.155865 2025] [security2:error] [pid 21964:tid 21964] [client 104.207.55.98:22107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.theledman.net"] [uri "/.svn/wc.db"] [unique_id "aSULH6WD84sFDPbbM-GFUQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:15:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:15:33.605991 2025] [security2:error] [pid 4370:tid 4370] [client 104.207.55.98:41333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.medcoarabia.com"] [uri "/.svn/wc.db"] [unique_id "aSUDNXxTNGyPolyt_eW9IwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:18:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:18:18.315116 2025] [security2:error] [pid 3776:tid 3776] [client 104.207.55.98:25885] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hischurchatwork.iworklife.org"] [uri "/.env"] [unique_id "aST1yvOycD4okDSU1Uef0QAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:28:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:28:23.196124 2025] [security2:error] [pid 9973:tid 9973] [client 104.207.55.98:47613] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.luvmypuggle.com"] [uri "/.git/HEAD"] [unique_id "aSQlN1_yKRAjm4BEyvOpBgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:30:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:30:23.090229 2025] [security2:error] [pid 7259:tid 7259] [client 104.207.55.98:45745] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.goglobex.com"] [uri "/.git/HEAD"] [unique_id "aSQXn3EMkpq2VtgHwMIctgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack