๐ฉ๐ช
Jochen Pretli
2026-09-23 08:48:35
(1 day ago)
connection to honeypot
Email Spam
Port Scan
๐ง๐ช
madeit
2026-09-21 16:22:45
(2 days ago)
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 18:12:44
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-11 17:44:09
(1 week ago)
Web App Attack
๐ธ๐ช
nekopavel
2026-09-10 02:56:01
(2 weeks ago)
104.23.160.118 - - [10/Sep/2026:04:56:00 +0200]"GET /.env.live HTTP/1.1" 301 162"-" thighs.moe "Mozi ...
show more
104.23.160.118 - - [10/Sep/2026:04:56:00 +0200]"GET /.env.live HTTP/1.1" 301 162"-" thighs.moe "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.000" "-""Portland" "US"
104.23.160.118 - - [10/Sep/2026:04:56:00 +0200]"GET /.env.live HTTP/1.1" 301 162"-" thighs.moe "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.000" "-""Portland" "US"
104.23.160.118 - - [10/Sep/2026:04:56:00 +0200]"GET /.env.live HTTP/1.1" 301 162"-" thighs.moe "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.000" "-""Portland" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-03 08:59:18
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
jbettigole
2026-08-29 06:27:40
(3 weeks ago)
MikroTik RouterOS: repeated connection attempts against non-public admin/service ports (SSH/Telnet/F ...
show more
MikroTik RouterOS: repeated connection attempts against non-public admin/service ports (SSH/Telnet/FTP/Winbox/API/WWW) triggering escalating 5m/15m/1h/1d blacklist
show less
Brute-Force
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 06:01:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:01:36.815130 2026] [security2:error] [pid 22985:tid 22985] [client 104.23.160.118:13224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "croixlac.com"] [uri "/.git/config"] [unique_id "apEkQBgjaS9YPdA_ALRIfwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-08-28 05:20:26
(3 weeks ago)
.git/config scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:07:34
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:07:29.682354 2026] [security2:error] [pid 27739:tid 27739] [client 104.23.160.118:13594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.creertest.com"] [uri "/.git/HEAD"] [unique_id "apDfUblsG7aUsbubo-eRXgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:03:51
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 18:43:26
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:43:17.647004 2026] [security2:error] [pid 26669:tid 26669] [client 104.23.160.118:13000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.plazacristal.com"] [uri "/.git/HEAD"] [unique_id "apCFRbQ3gXuImB5rgcPoaQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:38:05
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:37:57.499154 2026] [security2:error] [pid 7546:tid 7546] [client 104.23.160.118:14068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.constructiondomex.com"] [uri "/.git/config"] [unique_id "apA9tcvZ2jPobpZ63Xv2igAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:12:11
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:12:03.476482 2026] [security2:error] [pid 12315:tid 12375] [client 104.23.160.118:10833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siraceservices.com"] [uri "/.git/HEAD"] [unique_id "apA3ozoMFjjy67VRK2y2SAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:46:28
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:46:21.749771 2026] [security2:error] [pid 7783:tid 7783] [client 104.23.160.118:11348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.djmrmusic.com"] [uri "/.git/config"] [unique_id "apAxnTW1Y5uboMY_XNv0YQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack