๐บ๐ธ
TPI-Abuse
2026-08-24 16:57:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:57:18.359777 2026] [security2:error] [pid 12774:tid 12774] [client 104.23.160.151:13125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thebrotherhoodlounge.com"] [uri "/.git/config"] [unique_id "aox37ueN-atMg65IotoSJQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
eyesilyurt
2026-08-24 16:27:46
(2 hours ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐ฉ๐ช
Grossmann-Gruppe
2026-08-23 15:12:56
(1 day ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐ณ๐ด
jad-abuse
2026-08-20 06:23:34
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 01:02:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 21:01:38.471099 2026] [security2:error] [pid 6851:tid 6875] [client 104.23.160.151:12138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dermatologistdallas.com.aafm.us"] [uri "/.git/HEAD"] [unique_id "aoZR8rH1JTzxbHJ6DACpHwAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:17:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:17:45.616367 2026] [security2:error] [pid 18307:tid 18307] [client 104.23.160.151:10329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michaelandkatie.us"] [uri "/.git/HEAD"] [unique_id "aoZHqcMamD3zVwp21W65UQAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 22:28:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 18:28:47.507987 2026] [security2:error] [pid 14018:tid 14018] [client 104.23.160.151:14317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aarce.me"] [uri "/.git/HEAD"] [unique_id "aoYuHwNFc-sl6netuPcCpAAAAH0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 13:48:03
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 09:47:57.847133 2026] [security2:error] [pid 10359:tid 10359] [client 104.23.160.151:13135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.greybird.cc"] [uri "/.git/config"] [unique_id "aoW0DVA4msGHe54OXtOF3gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-15 11:44:22
(1 week ago)
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-07-18 05:19:47
(1 month ago)
(CT) IP 104.23.160.151 (US/United States/Oregon/Portland/-/[AS13335 CLOUDFLARENET]) found to have 10 ...
show more
(CT) IP 104.23.160.151 (US/United States/Oregon/Portland/-/[AS13335 CLOUDFLARENET]) found to have 102 connections (0-srv1)
show less
Hacking
๐บ๐ธ
mawan
2026-07-15 06:55:09
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-07-08 14:05:17
(1 month ago)
(CT) IP 104.23.160.151 (US/United States/Oregon/Portland/-/[AS13335 CLOUDFLARENET]) found to have 11 ...
show more
(CT) IP 104.23.160.151 (US/United States/Oregon/Portland/-/[AS13335 CLOUDFLARENET]) found to have 115 connections (0-srv1)
show less
Hacking
๐บ๐ธ
Starburst SysOp Team
2026-06-16 19:45:50
(2 months ago)
(CT) IP 104.23.160.151 (US/United States/Oregon/Portland/-/[AS13335 CLOUDFLARENET]) found to have 10 ...
show more
(CT) IP 104.23.160.151 (US/United States/Oregon/Portland/-/[AS13335 CLOUDFLARENET]) found to have 101 connections (0-srv1)
show less
Hacking
๐ณ๐ฑ
COMPLEX
2026-06-07 00:26:54
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 80
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-03 14:54:36
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.160.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 10:54:28.951159 2026] [security2:error] [pid 7621:tid 7621] [client 104.23.160.151:10424] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.cctaxpro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.cctaxpro.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aiBAJJS-g2ySovJRpYrCFwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack