๐บ๐ธ
TPI-Abuse
2026-10-01 12:30:43
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:30:40.564881 2026] [security2:error] [pid 30186:tid 30186] [client 104.23.187.215:12964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thompsonboatworks.com"] [uri "/wp-config.php"] [unique_id "ar5ScPen2sEpS6Ob_qIIBAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:41:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:41:26.890658 2026] [security2:error] [pid 32544:tid 32544] [client 104.23.187.215:10180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.greensborolimobus.com"] [uri "/wp-config.php"] [unique_id "ar5G5jPncmW-9ZSfhIwz-QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 07:57:16
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 03:57:10.833285 2026] [security2:error] [pid 10744:tid 10795] [client 104.23.187.215:13712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pref-realestate.com"] [uri "/.htaccess"] [unique_id "ar4SVv4gsOxQsVNnjlGgvAAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:51:43
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:51:36.662347 2026] [security2:error] [pid 19500:tid 19500] [client 104.23.187.215:12210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||yellowbrickfoundation.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "yellowbrickfoundation.com"] [uri "/index.php.bak"] [unique_id "ar2umOQfNsOqRVYjECTHLAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-28 15:26:39
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-18 19:47:47
(2 weeks ago)
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 04:36:48
(3 weeks ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9b ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9br2dhw9iulptrg3dmcbkxl | Client Tool: (no user-agent specified)
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-31 14:03:20
(1 month ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 2 hits.
show less
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-08-23 20:49:57
(1 month ago)
23/Aug/2026:22:49:56.094774 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
23/Aug/2026:22:49:56.094774 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.187.215] ModSecurity: Multipart parsing error: Multipart: No boundaries found in payload. [hostname "el-hacker.org"] [uri "/"] [unique_id "aotc9Ki_erEAlu3zO3p2EAAEinc"]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 05:26:28
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-15 17:06:17
(1 month ago)
Web App Attack
๐ง๐ช
madeit
2026-08-05 17:10:00
(2 months ago)
Web App Attack
๐ฆ๐น
Renรฉ Hickersberger
2026-07-21 22:03:01
(2 months ago)
malicious bot detected: violations="hit-honeypot"; user_agent="[redacted]"
Web App Attack
๐ฌ๐ง
CrystalMaker
2026-07-02 01:30:59
(3 months ago)
Vulnerability scan - GET /apache2.conf HTTP/2.0
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-31 04:37:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 00:37:54.990756 2026] [security2:error] [pid 13055:tid 13055] [client 104.23.187.215:13270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.chadfishman.com"] [uri "/.env.local"] [unique_id "actPomrsG_w69nw-HBF6-wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack