๐บ๐ฆ
URAN Publishing Service
2026-09-30 04:27:42
(6 days ago)
[30/Sep/2026:07:27:41 +0300] -- 207.175.208.77 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[30/Sep/2026:07:27:41 +0300] -- 207.175.208.77 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 22:59:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 207.175.208.77 (77.208.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.208.77 (77.208.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 18:59:14.242509 2026] [security2:error] [pid 19963:tid 19963] [client 207.175.208.77:58352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magodarman.com"] [uri "/.git/config"] [unique_id "arrxQjW8-i3zfOeeSXfD9QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-26 22:02:56
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-25.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-26 19:26:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 207.175.208.77 (77.208.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.208.77 (77.208.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 15:26:45.762115 2026] [security2:error] [pid 8345:tid 8345] [client 207.175.208.77:52266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cassimandabdallah.williamgilcher.com"] [uri "/.git/config"] [unique_id "argcdTqEuz-dgqdtRpQYOAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:43:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 207.175.208.77 (77.208.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.208.77 (77.208.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:43:35.106252 2026] [security2:error] [pid 17928:tid 17928] [client 207.175.208.77:45704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.urban-tails.com"] [uri "/.git/config"] [unique_id "arfoJ1UHFzk2CJAmw_lPIwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-25 22:00:39
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-25
Web App Attack
SSH
Hacking
Anonymous
2026-09-25 05:09:25
(1 week ago)
Automatically blocked after 3 security events. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 3 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:00:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 207.175.208.77 (77.208.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.208.77 (77.208.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:00:46.569491 2026] [security2:error] [pid 25702:tid 25702] [client 207.175.208.77:33684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.supportourlibrary.org"] [uri "/.git/config"] [unique_id "arVlTpVAL9J3v5JxDqh-uAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Francisco Vallejo
2026-09-23 09:03:21
(1 week ago)
[Wed Sep 23 11:03:21.045237 2026] [authz_core:error] [pid 1540326:tid 126352233592512] [client 207.1 ...
show more
[Wed Sep 23 11:03:21.045237 2026] [authz_core:error] [pid 1540326:tid 126352233592512] [client 207.175.208.77:37672] AH01630: client denied by server configuration: /var/www/franvallejo/.git/config
[Wed Sep 23 11:03:21.107563 2026] [authz_core:error] [pid 1540326:tid 126352183236288] [client 207.175.208.77:37672] AH01630: client denied by server configuration: /var/www/franvallejo/.env
[Wed Sep 23 11:03:21.135232 2026] [authz_core:error] [pid 1540326:tid 126352082589376] [client 207.175.208.77:37672] AH01630: client denied by server configuration: /var/www/franvallejo/.env.local
[Wed Sep 23 11:03:21.163339 2026] [authz_core:error] [pid 1540326:tid 126352216807104] [client 207.175.208.77:37672] AH01630: client denied by server configuration: /var/www/franvallejo/.env.production
[Wed Sep 23 11:03:21.190944 2026] [authz_core:error] [pid 1540326:tid 126352090982080] [client 207.175.208.77:37672] AH01630: client denied by server configuration: /var/www/franvallejo/.env.staging
...
show less
Brute-Force
SSH
๐ฎ๐น
VHosting
2026-09-23 08:50:06
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2026-09-22 10:44:44
(2 weeks ago)
http-sensitive-files - IP: 207.175.208.77 - time="2026-09-22T12:44:44+02:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 207.175.208.77 - time="2026-09-22T12:44:44+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 207.175.208.77 (US/396982) : 4h ban on Ip 207.175.208.77" module=db
show less
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-09-21 01:14:06
(2 weeks ago)
tried to access server backup files
Web App Attack