๐ฌ๐ง
myintarweb
2026-02-15 12:24:41
(3 months ago)
104.207.61.37 - - [15/Feb/2026:12:24:41 +0000] 80 "GET /.env.staging HTTP/1.1" 301 1681 "-" "Mozilla ...
show more
104.207.61.37 - - [15/Feb/2026:12:24:41 +0000] 80 "GET /.env.staging HTTP/1.1" 301 1681 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 11:56:01
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:55:56.527814 2026] [security2:error] [pid 11245:tid 11245] [client 104.207.61.37:62551] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "serpentstudios.com"] [uri "/api/.env"] [unique_id "aZG0TAMRx9jNGxxLljDf-QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-15 08:05:24
(3 months ago)
Scanning/Probing (27)
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-02-15 05:17:08
(3 months ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 05:01:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:01:45.360603 2026] [security2:error] [pid 12871:tid 12871] [client 104.207.61.37:42831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saratogaequity.com"] [uri "/new/.git/config"] [unique_id "aZFTOWGHDRwDkJ5Frjxd7QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:16:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:16:54.809505 2026] [security2:error] [pid 22331:tid 22331] [client 104.207.61.37:38987] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nrvoutdoors.com"] [uri "/new/.git/config"] [unique_id "aZFItqV_vh_aod_MxyATWgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:55:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:55:50.840959 2026] [security2:error] [pid 22097:tid 22097] [client 104.207.61.37:60283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noscentpro.com"] [uri "/api/.git/config"] [unique_id "aZFDxr2XQhuv_21iwW-7xgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:32:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:32:00.189842 2026] [security2:error] [pid 12916:tid 12916] [client 104.207.61.37:44143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "safwalu.com"] [uri "/.env.staging"] [unique_id "aZE-MEWofHIA0g0MNmH5egAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:15:45
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:15:42.137913 2026] [security2:error] [pid 23277:tid 23277] [client 104.207.61.37:62517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabras.com"] [uri "/.env"] [unique_id "aZE6XrYw5JX6VxteMlFiVAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-15 02:49:30
(3 months ago)
Blocking for trying to access an exploit file: /dev/.git/config
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-15 01:50:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:50:21.496479 2026] [security2:error] [pid 30235:tid 30235] [client 104.207.61.37:29173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "netcastcorp.com"] [uri "/frontend/.env"] [unique_id "aZEmXSW7H7hisEdVA3EIMwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:25:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:25:35.959300 2026] [security2:error] [pid 15119:tid 15119] [client 104.207.61.37:23219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ncogtrains.com"] [uri "/v2/.git/config"] [unique_id "aZEgj4OXUam00P5m8GPqFgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-02-15 01:12:49
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐จ๐ญ
Origon
2026-02-15 00:51:06
(3 months ago)
http-sensitive-files - IP: 104.207.61.37 - time="2026-02-15T01:51:06+01:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 104.207.61.37 - time="2026-02-15T01:51:06+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 104.207.61.37 (CA/200373) : 4h ban on Ip 104.207.61.37" module=db
show less
Web App Attack
๐ฆ๐บ
MAGIC
2026-01-19 03:06:57
(4 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot