๐ฌ๐ง
sandra361
2026-06-06 19:18:01
(1 week ago)
Port scan detected: 5 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC= ...
show more
Port scan detected: 5 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=104.23.175.103 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=56580 DF PROTO=TCP SPT=11996 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
Anonymous
2026-05-13 06:01:15
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
mawan
2026-05-12 20:44:12
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 07:08:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.175.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.175.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 03:08:35.215143 2026] [security2:error] [pid 24589:tid 24596] [client 104.23.175.103:12412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clmtic.net"] [uri "/.git/config"] [unique_id "af7dc7_g5TkwbkLJ6iZkEgAAAAU"], referer: https://www.google.com/search?q=clmtic.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 07:40:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.175.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.175.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 03:40:27.046149 2026] [security2:error] [pid 6633:tid 6633] [client 104.23.175.103:9982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sawtoothstudios.com"] [uri "/.git/config"] [unique_id "af2Ta38x8lRwAG_SC1GzvAAAABc"], referer: https://www.google.com/search?q=cpanel.sawtoothstudios.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-05 14:35:50
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-03-11 08:28:26
(3 months ago)
104.23.175.103 - - [11/Mar/2026:10:28:23 +0200] "GET /public/wp-content/index.php HTTP/1.0" 404 460 ...
show more
104.23.175.103 - - [11/Mar/2026:10:28:23 +0200] "GET /public/wp-content/index.php HTTP/1.0" 404 460 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.175.103 - - [11/Mar/2026:10:28:23 +0200] "GET /public/wp-content/index.php HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.175.103 - - [11/Mar/2026:10:28:26 +0200] "GET /wp-content/plugins/pwnd/as.php HTTP/1.0" 404 460 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.175.103 - - [11/Mar/2026:10:28:26 +0200] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.175.103 - - [11/Mar/2026:10:28:26 +0200] "GET /wp-content/upgrade/index.php HTTP/1.0" 404 460 "-" "Mozilla/5.0 (Win
...
show less
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-02-28 05:27:18
(3 months ago)
28/Feb/2026:06:27:18.308404 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Feb/2026:06:27:18.308404 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.103] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 's)k1o' [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "66"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: s)k1o found within ARGS:orgId: 1\\\\x22) WHERE 7012=7012%(%/%*%!%5%0%0%0%0%s%e%L%E%c%t%*%/%/%*%*%/%1%1%5%3%/%*%*%/%/%*%!%5%0%0%0%0%f%r%o%m%*%/%(%/%*%!%5%0%0%0%0%s%e%L%e%c%t%*%/%/%*%*%/%/%*%!%5%0%0%0%0%C%O%U%N%T%*%/%(%*%)%,%/%*%!%5%0%0%0%0%c%O%n%c%a%t%*%/%(%'%~%'%,%(%/%*%!%5%0%0%0%0%s%e%l%E%c%T%*%/%/%*%*%/%(%E%L%t%(%1%1%5%3%=%1%1%5%3%,%1%)%)%)%,%'%~%'%,%F%l%O%o%R%(%r%A%N%d%(%0%)%*%2%)%)%x%/%*%*%/%/%*%!%5%0%0%0%0%f%R%O%M%*%/%/%*%*%/%I%n%f%o%R%M%A%T%I%o%N%_%S%C%H%E%m%a%.%P%l%u%G%I%n%S%/%*%*%/%/%*..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platfo
...
show less
Hacking
Web App Attack
๐ฉ๐ช
403veli
2025-12-30 05:51:23
(5 months ago)
Confirmed malicious activity observed via T-Pot honeypot Observed 33 events on port 80 (unknown) fro ...
show more
Confirmed malicious activity observed via T-Pot honeypot Observed 33 events on port 80 (unknown) from 2025-12-30T05:51:23+00:00 to 2025-12-30T05:52:31.477000+00:00. Sample: {"dest_port": 80, "src_port": 41537, "src_ip": "104.23.175.103"}
show less
Port Scan
๐บ๐ธ
mawan
2025-11-08 07:35:26
(7 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ธ๐ฌ
pusathosting.com
2025-10-19 12:00:12
(7 months ago)
24ds22 bruteforce
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2025-10-16 18:50:38
(7 months ago)
16/Oct/2025:20:50:37.644208 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
16/Oct/2025:20:50:37.644208 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.103] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".dll"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "el-hacker.org"] [uri "/manuales/Cracking/snd-reve
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-10-16 12:39:48
(7 months ago)
16/Oct/2025:14:39:48.496006 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
16/Oct/2025:14:39:48.496006 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.103] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".dll"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "el-hacker.org"] [uri "/manuales/Cracking/snd-reve
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-10-14 10:54:45
(7 months ago)
14/Oct/2025:12:54:45.072093 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
14/Oct/2025:12:54:45.072093 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.175.103] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sys"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "el-hacker.org"] [uri "/manuales/Cracking/ARTeam_e
...
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2025-10-08 17:40:30
(8 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack