๐ณ๐ฑ
jjnxpct
2026-02-20 04:53:48
(3 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /site/.git/config (Rule ID: 930130) - Restricted File Access Attempt
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-18 11:44:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:44:23.346801 2026] [security2:error] [pid 8305:tid 8305] [client 104.207.63.45:57651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wallpaperpro.com"] [uri "/frontend/.env"] [unique_id "aZWmF1c5c6P7f_91vmDrDwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:38:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:38:52.756501 2026] [security2:error] [pid 1493488:tid 1493488] [client 104.207.63.45:23447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garon.us"] [uri "/admin/.git/config"] [unique_id "aYpT7GOBBG0QPH6uxGo5igAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-02-09 09:47:20
(3 months ago)
GET /api/.git/config HTTP/1.1
Web App Attack
Anonymous
2026-01-26 03:04:17
(4 months ago)
2026-01-26T05:04:16.637194+02:00 zanati wp(www.sahpa.co.za)[579625]: Blocked authentication attempt ...
show more
2026-01-26T05:04:16.637194+02:00 zanati wp(www.sahpa.co.za)[579625]: Blocked authentication attempt for Ncube from 104.207.63.45
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-28 02:13:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 21:13:22.591026 2025] [security2:error] [pid 17804:tid 17804] [client 104.207.63.45:53251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arkansasbest.com"] [uri "/.git/HEAD"] [unique_id "aVCSQskmz7v3HC3fK6SbsAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-28 00:55:14
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 19:55:07.798144 2025] [security2:error] [pid 25024:tid 25024] [client 104.207.63.45:59539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidnevueconcerts.com"] [uri "/.git/HEAD"] [unique_id "aVB_673muUY-jRwbASGOiwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 21:06:35
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 16:06:27.596089 2025] [security2:error] [pid 22849:tid 22849] [client 104.207.63.45:15645] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "savannah-house.com"] [uri "/.env"] [unique_id "aVBKU6xU7PWz_uwb-7HCigAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-27 19:32:01
(5 months ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 17:49:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 12:49:43.183064 2025] [security2:error] [pid 5273:tid 5273] [client 104.207.63.45:29823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homenetserv.com"] [uri "/.svn/wc.db"] [unique_id "aVAcN5lhpVPxJdSFgoGxSwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 17:25:09
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 12:25:05.192156 2025] [security2:error] [pid 8379:tid 8379] [client 104.207.63.45:41435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brigittecavanagh.com"] [uri "/.env"] [unique_id "aVAWcdorJLHVDRefxJ5dvQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-22 22:07:06
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ฆ๐บ
MAGIC
2025-12-07 00:06:07
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-25 07:28:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:27:51.079739 2025] [security2:error] [pid 28211:tid 28211] [client 104.207.63.45:44365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.randallbrooks.com"] [uri "/.svn/wc.db"] [unique_id "aSVad--cpn9xNTmrDf8N0AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2025-11-25 07:01:39
(6 months ago)
trolling for resource vulnerabilities
Web App Attack