๐บ๐ธ
TPI-Abuse
2026-10-01 12:50:55
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:50:51.500418 2026] [security2:error] [pid 27908:tid 27908] [client 104.23.187.66:14242] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pjv.us|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pjv.us"] [uri "/index.php.bak"] [unique_id "ar5XK9YdWh6wSoevv4mntAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:40:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:40:55.421076 2026] [security2:error] [pid 10996:tid 10996] [client 104.23.187.66:13563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thechildrenscharity.net"] [uri "/wp-config.php.bak"] [unique_id "ar44tw_Cfi0uF9wSf0DaCQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 09:05:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:05:12.543027 2026] [security2:error] [pid 3286:tid 3286] [client 104.23.187.66:12767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkhorseyachting.com"] [uri "/wp-config.php"] [unique_id "ar4iSDNcZUNX_KLcVjKe2wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-30 19:36:06
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:51:26
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:51:18.977658 2026] [security2:error] [pid 29670:tid 29670] [client 104.23.187.66:14073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ptr.dutchlake.com"] [uri "/.htaccess"] [unique_id "ar0v9tSm1Ep-JzPoT1hS4AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-18 04:17:19
(2 weeks ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9b ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9br2dhw9iulptrg3dmcbkxl | Client Tool: (no user-agent specified)
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Richie
2026-09-17 07:02:45
(2 weeks ago)
[HOST1] WordPress probe: GET /wp-admin/admin-ajax.php -> HTTP 400; UA: Mozilla/5.0 (Windows NT 10.0; ...
show more
[HOST1] WordPress probe: GET /wp-admin/admin-ajax.php -> HTTP 400; UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-06 08:00:33
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 23:59:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 19:59:04.310561 2026] [security2:error] [pid 5136:tid 5136] [client 104.23.187.66:10168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spadina.passy.us"] [uri "/.env.local"] [unique_id "ajHjSHXXM6XHDPp8ZwksIQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-16 22:00:22
(3 months ago)
Auto-ban: >3000 req/min op 2026-06-16
Web App Attack
SSH
Hacking
๐ฉ๐ช
acadeova
2026-06-12 01:47:25
(3 months ago)
๐จ Recon detected (nft drop)
SRC=104.23.187.66
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=104.23.187.66
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฎ๐ฉ
sockominfo
2026-04-29 14:00:49
(5 months ago)
Access to sensitive configuration files detected., Access to sensitive files detected w/ specific bo ...
show more
Access to sensitive configuration files detected., Access to sensitive files detected w/ specific boundary.. Threat Score: 5.4/10 (MEDIUM). Confidence: 55%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 80%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Moderate. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-29 12:01:11
(5 months ago)
Access to sensitive configuration files detected., Access to sensitive files detected w/ specific bo ...
show more
Access to sensitive configuration files detected., Access to sensitive files detected w/ specific boundary.. Threat Score: 5.6/10 (MEDIUM). Confidence: 55%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 80%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-29 11:00:45
(5 months ago)
Access to sensitive configuration files detected., Access to sensitive files detected w/ specific bo ...
show more
Access to sensitive configuration files detected., Access to sensitive files detected w/ specific boundary.. Threat Score: 5.7/10 (MEDIUM). Confidence: 55%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 80%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-29 10:00:19
(5 months ago)
Access to sensitive configuration files detected.. Threat Score: 7.1/10 (HIGH). Reported by Tangeran ...
show more
Access to sensitive configuration files detected.. Threat Score: 7.1/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack