๐บ๐ธ
TPI-Abuse
2026-02-23 14:44:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 09:44:27.538667 2026] [security2:error] [pid 3329:tid 3357] [client 104.207.63.3:24129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "besfixedwireless.com.exede-sales.com"] [uri "/.git/config"] [unique_id "aZxny4lCXX14Kq66x8s5ugAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 12:13:08
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 07:13:00.976377 2026] [security2:error] [pid 7121:tid 7151] [client 104.207.63.3:16115] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adprosfla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adprosfla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZhPzE3qzak5-cvxIyKoOwAAABY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-02-10 21:04:52
(3 months ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:45:20
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:45:15.696089 2026] [security2:error] [pid 11511:tid 11511] [client 104.207.63.3:38319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ibiocat.com"] [uri "/new/.git/config"] [unique_id "aYqpy736s19MhdifQ2skyQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-09 22:59:56
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-09
Hacking
Web App Attack
SSH
๐บ๐ธ
myagent.site
2026-02-09 20:06:54
(3 months ago)
Blocking for trying to access an exploit file: /.env.save
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-17 10:35:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 05:35:36.337056 2026] [security2:error] [pid 30553:tid 30553] [client 104.207.63.3:32367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.barriebrown.com"] [uri "/.env"] [unique_id "aWtl-FSv4FDtPZYYedcwiAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 05:44:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 00:44:05.280619 2026] [security2:error] [pid 5661:tid 5661] [client 104.207.63.3:23831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.central-wi-coal-sales.com"] [uri "/.env"] [unique_id "aWshpe0CYCPYlRaB_yTQ8wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2026-01-10 09:30:08
(4 months ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-30 10:59:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 05:59:22.630349 2025] [security2:error] [pid 22461:tid 22461] [client 104.207.63.3:21297] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aliciagrant.com"] [uri "/.svn/wc.db"] [unique_id "aVOwirGgKWmQRGhXoYpRpwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2025-12-30 10:25:38
(5 months ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 06:45:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:45:03.260145 2025] [security2:error] [pid 14368:tid 14368] [client 104.207.63.3:25217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airlinechristmascards.com"] [uri "/.env"] [unique_id "aVIjb58ryjeBDiXMR98hYQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-11-27 02:59:08
(6 months ago)
ThreatBook Intelligence: http_proxy,Zombie more details on https://threatbook.io/ip/104.207.63.3
202 ...
show more
ThreatBook Intelligence: http_proxy,Zombie more details on https://threatbook.io/ip/104.207.63.3
2025-11-26 17:34:13 /.svn/wc.db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 11:31:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:31:16.690634 2025] [security2:error] [pid 9655:tid 9655] [client 104.207.63.3:32403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.alexlacruz.com"] [uri "/.git/HEAD"] [unique_id "aSblBEqZfk3o1yRL0lW23wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:44:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:44:28.222850 2025] [security2:error] [pid 28782:tid 28782] [client 104.207.63.3:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.caspina.com"] [uri "/.svn/wc.db"] [unique_id "aSa97JQcfDK9gs0o49WP1gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack