๐บ๐ธ
TPI-Abuse
2026-02-12 06:28:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 01:28:41.080420 2026] [security2:error] [pid 23494:tid 23494] [client 104.207.59.182:36979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artsun.com"] [uri "/.git/config"] [unique_id "aY1zGY6v1J2A-h_RBjtVLwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 17:58:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 12:58:27.823027 2026] [security2:error] [pid 29727:tid 29727] [client 104.207.59.182:61283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arabou.co"] [uri "/.env.staging"] [unique_id "aYzDQ0PmOreRJwcwtaHVAAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 15:55:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 10:54:59.608328 2026] [security2:error] [pid 11837:tid 11837] [client 104.207.59.182:24269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antiterrorismbooks.net"] [uri "/admin/.env"] [unique_id "aYtU021ugGriBwXZBokbRQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 06:25:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 01:25:50.556438 2026] [security2:error] [pid 2038943:tid 2038943] [client 104.207.59.182:50055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kompassconsulting.com"] [uri "/backup/.git/config"] [unique_id "aYrPbiEs7UFfMadYYJKc9wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:20:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:20:21.926407 2026] [security2:error] [pid 26524:tid 26524] [client 104.207.59.182:23163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maerynray.com"] [uri "/app/.env"] [unique_id "aYqj9e4T-suCaUDNcnX-cwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:27:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:27:53.384750 2026] [security2:error] [pid 14816:tid 14816] [client 104.207.59.182:23017] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hudswell.com"] [uri "/.env.local"] [unique_id "aYp7iVEmJoE40OieHmBSFgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-02-09 22:04:43
(3 months ago)
Login credentials theft attempt
Hacking
๐ช๐ธ
10dencehispahard SL
2026-01-20 06:40:07
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ซ๐ท
dynamix
2026-01-04 00:10:06
(5 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 06:03:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:03:35.609649 2025] [security2:error] [pid 24847:tid 24847] [client 104.207.59.182:28843] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.savingshvac.com"] [uri "/.env"] [unique_id "aSaYN6H9baoy5HRXyIAf3gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:57:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:57:23.963800 2025] [security2:error] [pid 17951:tid 17951] [client 104.207.59.182:43593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kenometer.recollected.net"] [uri "/.git/HEAD"] [unique_id "aSZQc3vtXDmm2YKcp-6sKAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-25 22:26:45
(6 months ago)
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:19:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:19:17.785389 2025] [security2:error] [pid 12239:tid 12239] [client 104.207.59.182:36377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.autobee.biz"] [uri "/.git/HEAD"] [unique_id "aSVYdXtXTqWUxbXh5xL7VgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:47:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:47:12.059633 2025] [security2:error] [pid 1647139:tid 1647175] [client 104.207.59.182:31571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cornell61.org"] [uri "/.svn/wc.db"] [unique_id "aSUKoJ5eMzOQPKYL6rL4rwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
David Ferneding
2025-11-24 22:58:18
(6 months ago)
Blocked by UFW (TCP on 80)
Source port: 40755
TTL: 56
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 40755
TTL: 56
Packet length: 60
TOS: 0x00
This report (for 104.207.59.182) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack