๐ฌ๐ง
sandra361
2026-06-06 04:22:02
(5 days ago)
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=104 ...
show more
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=104.23.175.102 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=33715 DF PROTO=TCP SPT=10782 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐ฌ๐ง
sandra361
2026-05-28 06:29:01
(1 week ago)
Port scan detected: 6 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC= ...
show more
Port scan detected: 6 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=104.23.175.102 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=57820 DF PROTO=TCP SPT=13183 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-08 08:36:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.175.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.175.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 04:35:50.374487 2026] [security2:error] [pid 15073:tid 15073] [client 104.23.175.102:10643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onlinesoldier.com"] [uri "/.env.production.local"] [unique_id "af2gZo2waUyN2jMeKYSh6QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
security.yc3a.com
2026-01-31 09:26:28
(4 months ago)
104.23.175.102 - - [31/Jan/2026:09:26:28 +0000] "GET /wp-login.php HTTP/2.0" 301 162 "https://www.go ...
show more
104.23.175.102 - - [31/Jan/2026:09:26:28 +0000] "GET /wp-login.php HTTP/2.0" 301 162 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2025-11-13 22:49:49
(6 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ช๐ธ
el-brujo
2025-10-20 21:38:30
(7 months ago)
20/Oct/2025:23:38:30.230422 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
20/Oct/2025:23:38:30.230422 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.102] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /cursos/udemy - docker mastery with kubernetes swarm from a docker captain/21 - devops and docker clips/168 - entrypoint in dockerfiles.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "el-hacker.org"] [uri "/Cursos/Udemy - Docker Mastery with Kubernetes Swarm from a Docker Captain/21 - DevOps and Docker Clips/168 - ENTRYPOINT in Dockerfiles.txt"] [unique_id "aPar1vuJBEVV9AYB6fU7JwAABYU"]
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-10-19 05:30:18
(7 months ago)
19/Oct/2025:07:30:18.203933 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
19/Oct/2025:07:30:18.203933 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.102] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /cursos/udemy - docker mastery with kubernetes swarm from a docker captain/10 - swarm app lifecycle/84 - healthcheck in dockerfile docker docs.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "el-hacker.org"] [uri "/Cursos/Udemy - Docker Mastery with Kubernetes Swarm from a Docker Captain/10 - Swarm App Lifecycle/84 - HEALTHCHECK in Dockerfile Docker Docs.txt"] [unique_id "aPR3aljLGhqYAsyFIziUxg
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-10-16 13:19:52
(7 months ago)
16/Oct/2025:15:19:52.328166 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
16/Oct/2025:15:19:52.328166 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.102] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "el-hacker.org"] [uri "/.env"] [unique_id "aPDw-MiwQ_eXuxYTV8kUSAAABkA"]
...
show less
Hacking
Web App Attack
๐ธ๐ฌ
pusathosting.com
2025-10-05 07:00:08
(8 months ago)
24ds22 bruteforce
Brute-Force
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-10-01 23:12:34
(8 months ago)
2025-10-01 06:12:30 /inputs.php
2025-10-01 06:12:55 /pvt.php
2025-10-01 06:12:54 /beence.php
2025-10 ...
show more
2025-10-01 06:12:30 /inputs.php
2025-10-01 06:12:55 /pvt.php
2025-10-01 06:12:54 /beence.php
2025-10-01 06:13:40 /wp-content/upgrade/about.php
show less
Web App Attack
๐ช๐ธ
el-brujo
2025-09-19 07:16:49
(8 months ago)
19/Sep/2025:09:16:49.022813 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
19/Sep/2025:09:16:49.022813 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.102] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".BAK"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "el-hacker.org"] [uri "/manuales/Lenguajes de Prog
...
show less
Hacking
Web App Attack
๐ฎ๐ช
eyesilyurt
2025-09-13 12:33:19
(8 months ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐ช๐ธ
el-brujo
2025-09-07 11:20:17
(9 months ago)
07/Sep/2025:13:20:16.983329 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
07/Sep/2025:13:20:16.983329 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.102] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".BAK"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "el-hacker.org"] [uri "/manuales/Lenguajes de Prog
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-09-07 09:29:45
(9 months ago)
07/Sep/2025:11:29:45.152283 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
07/Sep/2025:11:29:45.152283 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.102] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".inc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "el-hacker.org"] [uri "/manuales/Lenguajes de Prog
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-09-07 08:22:20
(9 months ago)
07/Sep/2025:10:22:20.265863 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
07/Sep/2025:10:22:20.265863 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.102] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".BAK"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "el-hacker.org"] [uri "/manuales/Lenguajes de Prog
...
show less
Hacking
Web App Attack