๐ฉ๐ช
ghostwarriors
2026-08-21 10:50:17
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-21 10:48:38
(5 days ago)
104.22.101.137 - - [21/Aug/2026:12:48:36 +0200] "GET /db.php HTTP/2.0" 404 341 "-" "-"
104.22.101.13 ...
show more
104.22.101.137 - - [21/Aug/2026:12:48:36 +0200] "GET /db.php HTTP/2.0" 404 341 "-" "-"
104.22.101.137 - - [21/Aug/2026:12:48:36 +0200] "GET /wp.php HTTP/2.0" 404 55 "-" "-"
104.22.101.137 - - [21/Aug/2026:12:48:36 +0200] "GET /file6.php HTTP/2.0" 404 55 "-" "-"
104.22.101.137 - - [21/Aug/2026:12:48:37 +0200] "GET /bless24.php HTTP/2.0" 404 78 "-" "-"
104.22.101.137 - - [21/Aug/2026:12:48:37 +0200] "GET /link.php HTTP/2.0" 404 55 "-" "-"
104.22.101.137 - - [21/Aug/2026:12:48:37 +0200] "GET /packed.php HTTP/2.0" 404 55 "-" "-"
104.22.101.137 - - [21/Aug/2026:12:48:37 +0200] "GET /wp-includes/css/wp-conflg.php HTTP/2.0" 404 311 "-" "-"
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-18 03:04:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 23:04:10.695033 2026] [security2:error] [pid 20774:tid 20774] [client 104.22.101.137:14170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamroomrecording.com"] [uri "/.git/config"] [unique_id "aoPLqpi-47QpizfFlOdT9gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 13:20:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:20:37.240240 2026] [security2:error] [pid 4320:tid 4320] [client 104.22.101.137:13643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.heatherweathers.com"] [uri "/.git/HEAD"] [unique_id "aoMKpVmxWXjP3LoHhbXm2AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 12:44:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:44:23.034379 2026] [security2:error] [pid 8224:tid 8224] [client 104.22.101.137:10526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bonvivantorganics.com"] [uri "/.git/HEAD"] [unique_id "aoMCJydiHenoozIYQbUBiQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:47:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:47:11.576525 2026] [security2:error] [pid 32419:tid 32419] [client 104.22.101.137:13097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.quincysheetmetal.com"] [uri "/.git/config"] [unique_id "aoLYnzzb2_Va82rdleoS4gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:01:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:01:50.659123 2026] [security2:error] [pid 4656:tid 4656] [client 104.22.101.137:10103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jerusalem-temple-today.com"] [uri "/.git/config"] [unique_id "aoK_7iP-hgUBuXsf5L6hGQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:51:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:51:38.957515 2026] [security2:error] [pid 9303:tid 9303] [client 104.22.101.137:10408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dayspapass.com"] [uri "/.git/HEAD"] [unique_id "aoKhaswq9bDy2YDE5Vpi9QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:28:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:28:26.553167 2026] [security2:error] [pid 12610:tid 12610] [client 104.22.101.137:10149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.prometheusfalling.com"] [uri "/.git/config"] [unique_id "aoKb-mKWzKVhluCgmw-3qwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 11:07:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 07:07:29.857447 2026] [security2:error] [pid 5509:tid 5509] [client 104.22.101.137:14144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.miz-art.com"] [uri "/.git/config"] [unique_id "aoGZ8XFZX-xF4VHis2t8qgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 10:03:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:03:46.148294 2026] [security2:error] [pid 26308:tid 26308] [client 104.22.101.137:9970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.oiseauxsisters.com"] [uri "/.git/HEAD"] [unique_id "aoGLAgydXR6bcH5XxQZcRgAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:56:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:55:59.772721 2026] [security2:error] [pid 30282:tid 30282] [client 104.22.101.137:13354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sigridsnaturalfoods.com"] [uri "/.git/config"] [unique_id "aoE0z57fi9BVOMz6XGvkdwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-16 01:50:08
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-16 01:36:13
(1 week ago)
104.22.101.137 - - [16/Aug/2026:03:36:00 +0200] "GET /.well-known/file.php HTTP/2.0" 404 318 "-" "Mo ...
show more
104.22.101.137 - - [16/Aug/2026:03:36:00 +0200] "GET /.well-known/file.php HTTP/2.0" 404 318 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.22.101.137 - - [16/Aug/2026:03:36:00 +0200] "GET /.well-known/logs233/index.php HTTP/2.0" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.22.101.137 - - [16/Aug/2026:03:36:00 +0200] "GET /.well-known/pki-validation/ckyocyyp.php HTTP/2.0" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.22.101.137 - - [16/Aug/2026:03:36:00 +0200] "GET /.well-known/pki-validation/worksec.php HTTP/2.0" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.22.101.137 - - [16/Aug/2026:03:36:01 +0200] "GET /.well-known/radio.php HTTP/2.0" 404 78 "-" "Mozilla/5.0
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-11 20:02:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 16:02:46.882740 2026] [security2:error] [pid 369458:tid 369458] [client 104.22.101.137:12945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.worldofeconomics.com"] [uri "/.git/config"] [unique_id "ant_5m873ZswP2-MVPbK7QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack