๐ง๐ช
madeit
2026-08-23 14:34:05
(3 days ago)
Web App Attack
๐บ๐ธ
mawan
2026-08-20 16:53:29
(6 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-08-18 16:24:46
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:07:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:07:26.622206 2026] [security2:error] [pid 19010:tid 19010] [client 104.22.104.215:12838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sinko-intl.com"] [uri "/.git/HEAD"] [unique_id "aoLPTn5LRNKVdL3e3XMRvAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:40:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:40:34.117385 2026] [security2:error] [pid 29803:tid 29820] [client 104.22.104.215:13303] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mcwha.giere.us"] [uri "/.git/HEAD"] [unique_id "aoKe0uYwK8T66dvaNYoqBgAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-17 01:20:39
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ช
madeit
2026-08-11 05:46:03
(2 weeks ago)
Web App Attack
๐บ๐ธ
mawan
2026-07-13 06:36:12
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 11:35:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:35:45.715494 2026] [security2:error] [pid 16947:tid 16947] [client 104.22.104.215:10123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starvationacres.us"] [uri "/sftp-config.json"] [unique_id "agcFEfcL4M2UHWigiwKTTgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 04:19:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 00:19:03.976192 2026] [security2:error] [pid 25490:tid 25490] [client 104.22.104.215:12789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web19.dnchosting.com"] [uri "/.env.local"] [unique_id "agaet9OKkQ_dwruNd5-tyAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 05:54:49
(3 months ago)
(caddyscan) Scanner path probe from 104.22.104.215 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 104.22.104.215 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:05:14:12 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:05:24:43 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:05:54:47 +0000] "GET /wp-admin/includes/admin.php HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:05:54:47 +0000] "GET /wp-admin/css/admin.php HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:05:54:48 +0000] "GET /wp-admin/revision-long.php HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-14 04:51:13
(3 months ago)
(caddyscan) Scanner path probe from 104.22.104.215 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 104.22.104.215 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:04:24:19 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:04:31:45 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:04:33:45 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:04:33:48 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:04:51:10 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-14 04:10:36
(3 months ago)
(caddyscan) Scanner path probe from 104.22.104.215 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 104.22.104.215 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:03:47:53 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:03:52:33 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:04:06:03 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:04:09:22 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.215 - - [14/May/2026:04:10:31 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-09 20:29:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 16:29:27.476216 2026] [security2:error] [pid 6769:tid 6769] [client 104.22.104.215:13774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.paguilar.com"] [uri "/.git/config"] [unique_id "af-ZJzJxRBrQmcXRkBAzeQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 11:15:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 07:15:46.008340 2026] [security2:error] [pid 10718:tid 10718] [client 104.22.104.215:11960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maerynray.com"] [uri "/.git/config"] [unique_id "af8XYrAsxaeHemZ2g_23HAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack