Anonymous
2026-08-24 15:44:15
(1 day ago)
104.22.102.79 - - [24/Aug/2026:17:44:12 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
104.22.102.79 - - [24/Aug/2026:17:44:12 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.22.102.79 - - [24/Aug/2026:17:44:12 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.22.102.79 - - [24/Aug/2026:17:44:13 +0200] "GET //media/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.22.102.79 - - [24/Aug/2026:17:44:13 +0200] "GET //wp2/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.22.102.79 - - [24/Aug/2026:17:44:14 +0200] "GET //site/wp-includes/wlwmanifest.xml HTTP/1
...
show less
Brute-Force
Web App Attack
ππΊ
bcsaba
2026-08-23 12:24:59
(2 days ago)
Looking for json file on web server
104.22.102.79 - - [23/Aug/2026:14:24:56 +0200] "GET /secrets.jso ...
show more
Looking for json file on web server
104.22.102.79 - - [23/Aug/2026:14:24:56 +0200] "GET /secrets.json HTTP/2.0" 404 765 "https://www.google.com/search?q=*REDACTED*.*REDACTED*" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-08-18 21:59:17
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-18
Web App Attack
SSH
Hacking
π§πͺ
madeit
2026-08-18 01:28:32
(1 week ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 09:40:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:40:20.083263 2026] [security2:error] [pid 12019:tid 12045] [client 104.22.102.79:10283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativedemocrat.com"] [uri "/.git/HEAD"] [unique_id "aoLXBALOSqDpA_9BRs9puAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 07:02:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:02:42.501190 2026] [security2:error] [pid 5901:tid 5962] [client 104.22.102.79:11589] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ardentsi.com"] [uri "/.git/config"] [unique_id "aoKyEiRFkYbID9-WieN1BwAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 06:34:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:34:05.560011 2026] [security2:error] [pid 12433:tid 12433] [client 104.22.102.79:10253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aemcmullin.com"] [uri "/.git/config"] [unique_id "aoKrXajYQ_S0n87dqv5YtgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 04:45:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:45:29.767661 2026] [security2:error] [pid 16966:tid 16966] [client 104.22.102.79:13734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.anneoday.com"] [uri "/.git/config"] [unique_id "aoKR6XImWqMXh8UcqqLy4gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 10:50:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:50:03.251261 2026] [security2:error] [pid 13790:tid 13790] [client 104.22.102.79:13986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lewiscountyfair.ewingmissouri.com"] [uri "/.git/HEAD"] [unique_id "aoGV233rOoMu4oMf_x3TzAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 10:21:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:21:26.338191 2026] [security2:error] [pid 10891:tid 10891] [client 104.22.102.79:13006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.affourtit-bowmaker.com"] [uri "/.git/config"] [unique_id "aoGPJnDAtiC7P9mIgiClJAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 07:00:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:00:43.742207 2026] [security2:error] [pid 28564:tid 28564] [client 104.22.102.79:10028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.elcalamo.com"] [uri "/.git/config"] [unique_id "aoFgGzyZvLXyOUtjZm72EQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 06:14:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:14:19.513665 2026] [security2:error] [pid 16620:tid 16620] [client 104.22.102.79:12958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.takeapawsboston.com"] [uri "/.git/config"] [unique_id "aoFVO8YT6_ft8yg7dEv6ZgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 05:26:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:25:57.804850 2026] [security2:error] [pid 8851:tid 8851] [client 104.22.102.79:10142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bsa1688.com"] [uri "/.git/config"] [unique_id "aoFJ5flftgIqPmnwvsqDLAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 03:55:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:55:31.466786 2026] [security2:error] [pid 5699:tid 5699] [client 104.22.102.79:11303] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "servicios.imerka.com.mx"] [uri "/.git/HEAD"] [unique_id "aoE0s2WGZsKBvk5btgXAqgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-13 07:54:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 03:54:22.023647 2026] [security2:error] [pid 1285956:tid 1285956] [client 104.22.102.79:9255] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjtent.com"] [uri "/.git/config"] [unique_id "an14Ls9_e6ajZWQSbOK_cgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack