πΊπΈ
TPI-Abuse
2026-08-27 22:45:14
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:45:02.157451 2026] [security2:error] [pid 18142:tid 18142] [client 104.23.160.121:12203] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "freedrm.org"] [uri "/.git/HEAD"] [unique_id "apC97qaYXG0MtRWuRefaawAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
myintarweb
2026-08-27 15:04:38
(4 days ago)
104.23.160.121 - - [27/Aug/2026:16:04:36 +0100] 443 "GET /.git/HEAD HTTP/2.0" 404 1144 "-" "Mozilla/ ...
show more
104.23.160.121 - - [27/Aug/2026:16:04:36 +0100] 443 "GET /.git/HEAD HTTP/2.0" 404 1144 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 14:13:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:13:11.332054 2026] [security2:error] [pid 28349:tid 28349] [client 104.23.160.121:12195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.brushmileage.org"] [uri "/.git/HEAD"] [unique_id "apBF9-IUaI8mAWe-9LUnIAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-27 13:26:15
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 12:28:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:28:50.898391 2026] [security2:error] [pid 2278205:tid 2278262] [client 104.23.160.121:11678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mjkotob.com.oplconnect.com"] [uri "/.git/HEAD"] [unique_id "apAtguKMkSny_ZVB3hf9ygAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 06:38:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:38:53.214387 2026] [security2:error] [pid 24619:tid 24619] [client 104.23.160.121:11827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.numbulary.com"] [uri "/.git/config"] [unique_id "ao_bfcLsKX0Eg-MNkTRoRQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 22:16:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 18:16:45.436671 2026] [security2:error] [pid 1778:tid 1778] [client 104.23.160.121:9531] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bcbikini.com.puckerbikini.com"] [uri "/.git/config"] [unique_id "ao9lzXVuKe2nmoY7G9B9vwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-26 21:43:49
(4 days ago)
[27/Aug/2026:00:43:49 +0300] -- 104.23.160.121 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[27/Aug/2026:00:43:49 +0300] -- 104.23.160.121 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 18:47:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:47:11.288546 2026] [security2:error] [pid 22244:tid 22244] [client 104.23.160.121:10609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.z-mgmt.com"] [uri "/.git/HEAD"] [unique_id "ao80ryxPrudrtRxZkny4MAAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 18:06:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:06:48.729513 2026] [security2:error] [pid 25494:tid 25494] [client 104.23.160.121:10387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.arklatexds.com"] [uri "/.git/HEAD"] [unique_id "ao8rOBqV5mZY1CAaLw7kFgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-26 11:01:12
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 09:59:04
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:58:57.081412 2026] [security2:error] [pid 12350:tid 12350] [client 104.23.160.121:9969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mathewsdental.com"] [uri "/.git/config"] [unique_id "ao644SvK2pvQTJYEOu5m5QAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-26 09:49:28
(5 days ago)
Web App Attack
πΊπΈ
gerensat
2026-08-26 06:44:44
(5 days ago)
2026-08-26 03:44:44 | /.git/config | [] | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537. ...
show more
2026-08-26 03:44:44 | /.git/config | [] | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
show less
Web App Attack
π¬π§
SilverZippo
2026-08-25 21:31:37
(5 days ago)
Web App Attack
Web App Attack