๐ฉ๐ช
Carsten
2026-05-30 02:51:04
(6 days ago)
bad web bot
Port Scan
๐ฉ๐ช
4server
2026-04-21 04:19:49
(1 month ago)
[TueApr2106:19:44.5254262026][security2:error][pid2428967:tid2428979][client104.207.58.77:0]ModSecur ...
show more
[TueApr2106:19:44.5254262026][security2:error][pid2428967:tid2428979][client104.207.58.77:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"gm-swiss.ch\"][uri\"/database.sql\"][unique_id\"aeb64FHR_2-JIdnTJ8T0JAAAAIk\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 17:07:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 12:07:49.257679 2026] [security2:error] [pid 472:tid 472] [client 104.207.58.77:54249] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anxo.org"] [uri "/app/.git/config"] [unique_id "aYtl5ZHLtnR-IXd1tGTREgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฑ
ifiguero
2026-02-10 06:29:08
(3 months ago)
Web Attack (\x00\x00\x00\x00\x00). 7d ban
Web App Attack
๐บ๐ธ
jcbriar
2026-02-10 05:17:48
(3 months ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:43:01
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:42:53.393867 2026] [security2:error] [pid 1036082:tid 1036188] [client 104.207.58.77:9227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magazineofwallstreet.com"] [uri "/.env.production"] [unique_id "aYqpPQu5-PwVS0XMgJ_awgAAAgs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:27:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:27:46.572711 2026] [security2:error] [pid 14467:tid 14467] [client 104.207.58.77:40625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kimmimorikawa.com"] [uri "/.git/config"] [unique_id "aYqXokGW9lD6mXAm_2rZ9QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:21:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:21:27.765408 2026] [security2:error] [pid 23952:tid 23952] [client 104.207.58.77:63419] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotspringstips.com"] [uri "/app/.git/config"] [unique_id "aYpd5yL0Iycsc-LJ89-iIQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:50
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-02 10:05:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 05:05:29.708180 2025] [security2:error] [pid 424358:tid 424471] [client 104.207.58.77:11151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abundancebible.com"] [uri "/.git/HEAD"] [unique_id "aS656fp__Pmf5kEIOQBpsQAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:43:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:43:51.665175 2025] [security2:error] [pid 4699:tid 4699] [client 104.207.58.77:29137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clevercad.com"] [uri "/.env"] [unique_id "aS58l_3EAdGES1HY2Axg2QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:22:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:22:38.139186 2025] [security2:error] [pid 6260:tid 6260] [client 104.207.58.77:14071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clickableprize.com"] [uri "/.env"] [unique_id "aS53nkD7Uu41NpyWDsZ4cAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 04:05:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:05:52.091236 2025] [security2:error] [pid 3577:tid 3577] [client 104.207.58.77:10713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slimlaw.com"] [uri "/.env"] [unique_id "aS5loGcom_6XX17vuFwaXAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2025-12-02 00:56:53
(6 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐ฉ๐ช
london2038.com
2025-10-25 23:37:35
(7 months ago)
Connection atttempts against closed TCP ports
Oct 26 01:37:32 BLOCK SRC=104.207.58.77 LEN=60 TOS=0x0 ...
show more
Connection atttempts against closed TCP ports
Oct 26 01:37:32 BLOCK SRC=104.207.58.77 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=53823 DF PROTO=TCP SPT=36163 DPT=22 WINDOW=64240 RES=0x00 SYN
Oct 26 01:37:33 BLOCK SRC=104.207.58.77 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=53824 DF PROTO=TCP SPT=36163 DPT=22 WINDOW=64240 RES=0x00 SYN
Oct 26 01:37:34 BLOCK SRC=104.207.58.77 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=53825 DF PROTO=TCP SPT=36163 DPT=22 WINDOW=64240 RES=0x00 SYN
show less
Port Scan