๐ง๐ช
madeit
2026-09-04 16:04:49
(13 hours ago)
Web App Attack
๐บ๐ธ
freeutka
2026-05-07 01:27:15
(3 months ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐จ๐ฆ
yukon.ca
2026-04-13 10:52:19
(4 months ago)
Web Server Enforcement Violation: Sensitive Configuration File Disclosure
Port:80
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-03-30 12:30:23
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 08:30:15.597761 2026] [security2:error] [pid 29995:tid 29995] [client 104.23.187.150:9484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dunnretired.com"] [uri "/site/.env"] [unique_id "acps1_LZ13m4y1S78BsdrwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:25:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:25:50.632520 2026] [security2:error] [pid 20537:tid 20537] [client 104.23.187.150:14225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.edelbaumarchitect.com"] [uri "/.env.dev.local"] [unique_id "ab0SnldqsGG6T0q4QlIhgQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:13:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:13:27.933128 2026] [security2:error] [pid 17865:tid 17865] [client 104.23.187.150:13590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.volunteergems.com"] [uri "/docker/.env.local"] [unique_id "ab0Bp0r_tF5NE_W5F7zJyQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:09:00
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:08:50.548200 2026] [security2:error] [pid 31768:tid 31768] [client 104.23.187.150:13390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.krmartindale.com"] [uri "/app/.env"] [unique_id "aby6QlOI2zxbSkLRds1AJAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:42:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:41:55.194771 2026] [security2:error] [pid 23248:tid 23271] [client 104.23.187.150:12293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.northmiamichamber.org"] [uri "/.env.dev"] [unique_id "abvhA0CqZMRRg0jJDDpa4wAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:39:06
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:38:57.639454 2026] [security2:error] [pid 14922:tid 14922] [client 104.23.187.150:11539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dropzllc.directnic-support.rocks"] [uri "/.env.backup"] [unique_id "abvSQaJAUHnLrijwYmyPVgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
COMPLEX
2026-02-05 01:40:36
(7 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2025-10-06 17:18:55
(10 months ago)
104.23.187.150 - - [06/Oct/2025:20:17:59 +0300] "GET /cgi-bin/bypass.php HTTP/1.1" 404 498 "-" "Mozi ...
show more
104.23.187.150 - - [06/Oct/2025:20:17:59 +0300] "GET /cgi-bin/bypass.php HTTP/1.1" 404 498 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
104.23.187.150 - - [06/Oct/2025:20:18:54 +0300] "GET /cgi-bin/index.php HTTP/1.1" 404 498 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-10-04 10:29:16
(11 months ago)
104.23.187.150 - - [04/Oct/2025:13:29:03 +0300] "GET /cgi-bin/cloud.php HTTP/1.1" 404 498 "-" "Mozil ...
show more
104.23.187.150 - - [04/Oct/2025:13:29:03 +0300] "GET /cgi-bin/cloud.php HTTP/1.1" 404 498 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
104.23.187.150 - - [04/Oct/2025:13:29:15 +0300] "GET /cgi-bin/mariju.php HTTP/1.1" 404 498 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0"
...
show less
Web App Attack
Anonymous
2025-09-17 00:28:22
(11 months ago)
wp-login.php scan
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2025-09-08 21:00:24
(11 months ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐บ๐ธ
HJ5Ss4Ju
2025-09-02 07:33:05
(1 year ago)
WordPress XMLRPC scan :: 104.23.187.150 - - [02/Sep/2025:07:33:05 0000] "GET /xmlrpc.php?rsd HTTP/1 ...
show more
WordPress XMLRPC scan :: 104.23.187.150 - - [02/Sep/2025:07:33:05 0000] "GET /xmlrpc.php?rsd HTTP/1.1" 200 322 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack