Anonymous
2026-02-15 13:05:11
(3 months ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 11:22:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:22:35.776533 2026] [security2:error] [pid 18698:tid 18698] [client 104.207.60.73:17567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theurbanlogger.com"] [uri "/app/.env"] [unique_id "aZGsewhsLoRibtdhcJbGbwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-02-15 05:25:07
(3 months ago)
Try to access /api/.git/config
Web App Attack
Anonymous
2026-02-15 04:31:29
(3 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
πΊπΈ
TPI-Abuse
2026-02-15 03:47:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:46:59.271465 2026] [security2:error] [pid 21639:tid 21639] [client 104.207.60.73:27079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sternscape.com"] [uri "/api/.env"] [unique_id "aZFBs5DsBQZNU5xHlzpq_QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 03:22:20
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:22:17.326912 2026] [security2:error] [pid 7618:tid 7618] [client 104.207.60.73:31491] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starthreadingsalon.com"] [uri "/app/.env"] [unique_id "aZE76WubT626r9jqzMXrQQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 02:45:33
(3 months ago)
104.207.60.73 - - [15/Feb/2026:03:45:33 +0100] "GET /site/.git/config HTTP/1.1" 301 169 "-" "Mozilla ...
show more
104.207.60.73 - - [15/Feb/2026:03:45:33 +0100] "GET /site/.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 02:27:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:27:35.565810 2026] [security2:error] [pid 17806:tid 17806] [client 104.207.60.73:39831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mystudioinparis.com"] [uri "/new/.git/config"] [unique_id "aZEvF9qDMjzr4nMAvPT_DwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 01:57:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:57:09.907707 2026] [security2:error] [pid 2374930:tid 2374930] [client 104.207.60.73:22621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southsideaccountingservices.com"] [uri "/config/.env"] [unique_id "aZEn9QLQAzdWSaM4ogMR6wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
Origon
2026-02-15 01:11:18
(3 months ago)
http-sensitive-files - IP: 104.207.60.73 - time="2026-02-15T02:11:18+01:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 104.207.60.73 - time="2026-02-15T02:11:18+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 104.207.60.73 (CA/200373) : 4h ban on Ip 104.207.60.73" module=db
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 00:57:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 19:57:44.496467 2026] [security2:error] [pid 8930:tid 8930] [client 104.207.60.73:59631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lundtrading.com"] [uri "/.env.production"] [unique_id "aZEaCCxcEZZC-CMlOBE3-wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 00:01:22
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 19:01:17.981463 2026] [security2:error] [pid 17392:tid 17412] [client 104.207.60.73:36429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "longevityworkout.com"] [uri "/backup/.git/config"] [unique_id "aZEMzTIyJsQfjBl0rcjwTwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-14 23:10:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 18:10:02.717281 2026] [security2:error] [pid 21887:tid 21887] [client 104.207.60.73:12915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlepeopledelivery.com"] [uri "/wp/.git/config"] [unique_id "aZEAyt-M7l1-dNP8bH_49AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-14 21:49:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 16:49:08.054586 2026] [security2:error] [pid 779917:tid 779917] [client 104.207.60.73:16027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mlundp.com"] [uri "/new/.git/config"] [unique_id "aZDt1Alg1Ujf9sr9EMSViQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-14 21:27:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 16:27:12.884082 2026] [security2:error] [pid 401:tid 401] [client 104.207.60.73:61581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "missevelyn.com"] [uri "/.env"] [unique_id "aZDosJpFa9U-fgp6MEVI6QAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack