๐ง๐ช
voormedia
2026-02-26 00:52:07
(3 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-11 04:53:08
(3 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /config/.env (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .env found within REQUEST_FILENAME: /config/.env]
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 23:00:19
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐ณ๐ฟ
FaB Property Group
2026-02-10 11:45:20
(3 months ago)
Requested file: protected/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 06:07:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 01:07:32.776752 2026] [security2:error] [pid 10239:tid 10239] [client 104.207.63.211:56549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kokr.org"] [uri "/frontend/.env"] [unique_id "aYrLJPzCI6V-HDYB8MHCOQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 05:04:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:04:46.721011 2026] [security2:error] [pid 18514:tid 18514] [client 104.207.63.211:46937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idodat.com"] [uri "/.env.save"] [unique_id "aYq8btka-c1T01YJbzLUvwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 04:09:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:09:14.751416 2026] [security2:error] [pid 3085:tid 3085] [client 104.207.63.211:9269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iceofparadise.com"] [uri "/wp/.git/config"] [unique_id "aYqvaqjke71t3jzYkdDnWgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:16:53
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:16:48.583156 2026] [security2:error] [pid 32696:tid 32696] [client 104.207.63.211:27285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killeramps.com"] [uri "/app/.git/config"] [unique_id "aYqVEOMpRSPcVkfla-k8yAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:14:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:14:42.014327 2026] [security2:error] [pid 17734:tid 17734] [client 104.207.63.211:48545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotglassgallery.com"] [uri "/site/.git/config"] [unique_id "aYpcUuj8xQXwW5MbJBW0_gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-16 08:08:26
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
mashamal
2026-01-07 16:21:36
(4 months ago)
Vulnerability Probe
...
Web App Attack
Anonymous
2025-12-30 20:36:27
(5 months ago)
"GET /.aws/credentials HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-30 10:21:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 05:21:27.356922 2025] [security2:error] [pid 19084:tid 19084] [client 104.207.63.211:41521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lazymanvegan.com"] [uri "/.env"] [unique_id "aVOnp_e-21KJmkphHxr5EQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:08:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:08:29.788968 2025] [security2:error] [pid 25671:tid 25671] [client 104.207.63.211:49795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yubagals.com"] [uri "/.git/HEAD"] [unique_id "aVH-vfFMqvHrjo279TG2SgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
Johan Finn
2025-12-03 02:40:26
(6 months ago)
malicious activity
Web App Attack