Anonymous
2026-08-23 06:38:25
(21 hours ago)
Web scanner: GET /.git/config
Web App Attack
Hacking
๐ฉ๐ช
FeG Deutschland
2026-08-22 19:00:52
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-08-22 04:23:51
(1 day ago)
[SatAug2206:23:46.8609672026][security2:error][pid1982299:tid1982412][client104.23.160.91:0]ModSecur ...
show more
[SatAug2206:23:46.8609672026][security2:error][pid1982299:tid1982412][client104.23.160.91:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.allegraravizza.it\"][uri\"/.git/config\"][unique_id\"aokkUh3B5IOZhTKj4jQg8wAAANg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-08-21 01:03:44
(3 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 17:41:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 13:41:17.452188 2026] [security2:error] [pid 15074:tid 15074] [client 104.23.160.91:13318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.epetsure.co"] [uri "/.git/HEAD"] [unique_id "aoc8PW4C13ZNgjnXMXvcwAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 02:42:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 22:42:52.070850 2026] [security2:error] [pid 12951:tid 12951] [client 104.23.160.91:10555] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.casaniagara.com.mx"] [uri "/.git/config"] [unique_id "aoZprA6Ag0RzpOBoAsvHOwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:55:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:55:27.756432 2026] [security2:error] [pid 23544:tid 23544] [client 104.23.160.91:13068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.johnatuttle.us"] [uri "/.git/HEAD"] [unique_id "aoZQf-N78UN5L3J7iVfu7gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:11:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:10:26.409396 2026] [security2:error] [pid 20575:tid 20587] [client 104.23.160.91:10657] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aapmapac.aafm.us"] [uri "/.git/config"] [unique_id "aoZF8uwBNKI6z7FUElmOoQAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 13:43:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 09:43:44.174603 2026] [security2:error] [pid 8671:tid 8671] [client 104.23.160.91:12611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qxz.cc"] [uri "/.git/HEAD"] [unique_id "aoWzEB1rk9NAN_7Ux0Q2pQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-08-19 11:05:53
(4 days ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 06:12:28
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 02:12:22.584989 2026] [security2:error] [pid 28927:tid 28927] [client 104.23.160.91:12682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "album.navarrete.ws"] [uri "/.git/HEAD"] [unique_id "aoVJRgm_2kUxGgjraVOazwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-08-17 13:22:35
(6 days ago)
104.23.160.91 - - [17/Aug/2026:16:22:35 +0300] "GET /wp-json/ HTTP/2.0" 404 1853 "-" "Mozilla/5.0 (W ...
show more
104.23.160.91 - - [17/Aug/2026:16:22:35 +0300] "GET /wp-json/ HTTP/2.0" 404 1853 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-23 18:04:00
(2 months ago)
LH-Watcher: FAKE_ID [Fake facebook.com/externalhit]
Bad Web Bot
Anonymous
2026-06-18 17:46:01
(2 months ago)
LH-Watcher: FAKE_ID [Fake facebook.com/externalhit]
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-12 01:59:49
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.160.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 21:59:42.933165 2026] [security2:error] [pid 2686:tid 2686] [client 104.23.160.91:12833] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.harrygant.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.harrygant.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aitoDjP7MV6mlXrcFLTodwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack