๐บ๐ธ
TPI-Abuse
2026-02-12 02:08:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 21:08:25.305387 2026] [security2:error] [pid 2608:tid 2608] [client 104.207.62.178:59837] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arresteddevelopmentinsight.com"] [uri "/.env.production"] [unique_id "aY02GfeO8LSBlrT9NMZ74QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 15:34:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 10:34:21.857128 2026] [security2:error] [pid 10726:tid 10726] [client 104.207.62.178:54541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10mostwantedfugitives.com"] [uri "/.env.save"] [unique_id "aYtP_aBIJ8U4WsNGvxuENwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 05:30:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:30:39.777063 2026] [security2:error] [pid 919:tid 919] [client 104.207.62.178:54093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knoxbestos.com"] [uri "/frontend/.env"] [unique_id "aYrCf6Ib0FLWkYXdR6T3QAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 04:33:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:33:43.239853 2026] [security2:error] [pid 19268:tid 19268] [client 104.207.62.178:48123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icwcruisersguide.com"] [uri "/.env"] [unique_id "aYq1J3oVJJ7G1OIIxhDz-AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:32:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:32:06.133976 2026] [security2:error] [pid 19390:tid 19390] [client 104.207.62.178:32781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirt.us"] [uri "/backup/.git/config"] [unique_id "aYqmtmkCKfe4zJP6Tn5i7QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:54:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:54:31.329199 2026] [security2:error] [pid 6158:tid 6158] [client 104.207.62.178:17429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kenmalone.com"] [uri "/admin/.env"] [unique_id "aYpzt7jaquyJz9EWwSvOnAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 23:38:00
(3 months ago)
Blocking for trying to access an exploit file: /.env.production
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 21:21:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:21:33.242846 2026] [security2:error] [pid 11020:tid 11020] [client 104.207.62.178:41147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horsesaw.com"] [uri "/site/.git/config"] [unique_id "aYpP3SSBnki-9a5s1mfidAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 19:59:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 14:59:05.946057 2026] [security2:error] [pid 16795:tid 16795] [client 104.207.62.178:55509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homenetserv.com"] [uri "/admin/.env"] [unique_id "aYo8ia6DgMQGRb4EVz_j1gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-01-14 22:50:23
(4 months ago)
Kingcopy(AI-IDS):IP does Multiple AWS Environment Abuse
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 12:36:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 07:36:10.195324 2026] [security2:error] [pid 30726:tid 30726] [client 104.207.62.178:22755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networkzone.org"] [uri "/.svn/wc.db"] [unique_id "aWY8OmilfiM6zxa38FzbNQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-10 18:34:26
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.62.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 10 14:34:20.150217 2025] [security2:error] [pid 26140:tid 26140] [client 104.207.62.178:51021] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||forwardti.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "forwardti.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOlRrIHtgyrGmRTOlQSkpQAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-07 11:33:31
(1 year ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-06 21:43:16
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.04.06 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.04.06 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-04-04 19:45:45
(1 year ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.04 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.04.04 is noted in report timestamp
show less
Hacking
Brute-Force