๐ง๐ช
madeit
2026-10-05 19:31:29
(2 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:50:35
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:50:30.466964 2026] [security2:error] [pid 27887:tid 27887] [client 104.23.187.67:9908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pjv.us"] [uri "/wp-config.php"] [unique_id "ar5XFm9lMqlCcUbedllKwAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:41:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:41:14.988224 2026] [security2:error] [pid 7485:tid 7485] [client 104.23.187.67:12166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thechildrenscharity.net"] [uri "/wp-config.php"] [unique_id "ar44ytuiQb5bmdS03t2XDgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 09:05:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:05:17.363037 2026] [security2:error] [pid 3070:tid 3070] [client 104.23.187.67:9756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkhorseyachting.com"] [uri "/.git/config"] [unique_id "ar4iTTTeR-4VYvT_FD5iiQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 09:29:57
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-13 04:44:01
(1 month ago)
Web App Attack
๐ฌ๐ง
neo101
2026-08-11 05:52:30
(1 month ago)
Confirmed AWS Honeytoken Exploitation: Host actively executed stolen AWS Canary credentials (KEY-37: ...
show more
Confirmed AWS Honeytoken Exploitation: Host actively executed stolen AWS Canary credentials (KEY-37: AKIATU7L4S6W6QJVDBEF | Action: ListFoundationModels) harvested from decoy honeypot. Verified credential theft and unauthorized cloud API access.
show less
Hacking
Web App Attack
Anonymous
2026-08-02 07:56:01
(2 months ago)
104.23.187.67 - - [02/Aug/2026:09:55:57 +0200] "GET /env HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Macinto ...
show more
104.23.187.67 - - [02/Aug/2026:09:55:57 +0200] "GET /env HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_7_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
104.23.187.67 - - [02/Aug/2026:09:55:57 +0200] "GET /env HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_7_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
104.23.187.67 - - [02/Aug/2026:09:55:58 +0200] "GET /.env.local HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0"
104.23.187.67 - - [02/Aug/2026:09:55:58 +0200] "GET /.env.local HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0"
104.23.187.67 - - [02/Aug/2026:09:55:59 +0200] "GET /.env.production HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
104.23.187.67 - - [02/Aug/2026:09:55:59 +0200] "GET /.e
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-16 01:51:29
(2 months ago)
104.23.187.67 - - [16/Jul/2026:03:51:27 +0200] "GET /ict-materials.php HTTP/1.1" 404 445 "-" "Mozill ...
show more
104.23.187.67 - - [16/Jul/2026:03:51:27 +0200] "GET /ict-materials.php HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
104.23.187.67 - - [16/Jul/2026:03:51:27 +0200] "GET /ict-materials.php HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
104.23.187.67 - - [16/Jul/2026:03:51:28 +0200] "GET /ecz-past-papers.php HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
104.23.187.67 - - [16/Jul/2026:03:51:28 +0200] "GET /ecz-past-papers.php HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
104.23.187.67 - - [16/Jul/2026:03:51:28 +0200] "GET /gallery.php HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 23:59:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 19:59:08.841327 2026] [security2:error] [pid 11170:tid 11170] [client 104.23.187.67:13007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spadina.passy.us"] [uri "/.env.production"] [unique_id "ajHjTBModPidJiOkCKgZBAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 21:37:12
(3 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 11:43:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 07:43:26.876857 2026] [security2:error] [pid 2584:tid 2584] [client 104.23.187.67:12420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.catnameslist.bodybuildbid.com"] [uri "/.env.production"] [unique_id "ai6T3jRg65f0-6fgcugTXAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-29 09:00:45
(5 months ago)
Suspicious URL access., Access to sensitive configuration files detected., Access to sensitive files ...
show more
Suspicious URL access., Access to sensitive configuration files detected., Access to sensitive files detected w/ specific boundary.. Threat Score: 5.6/10 (MEDIUM). Confidence: 55%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 88%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Moderate. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-29 08:00:46
(5 months ago)
Suspicious URL access., Access to sensitive configuration files detected., Access to sensitive files ...
show more
Suspicious URL access., Access to sensitive configuration files detected., Access to sensitive files detected w/ specific boundary.. Threat Score: 5.7/10 (MEDIUM). Confidence: 55%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 88%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Moderate. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-29 07:00:51
(5 months ago)
Suspicious URL access., Access to sensitive configuration files detected., Access to sensitive files ...
show more
Suspicious URL access., Access to sensitive configuration files detected., Access to sensitive files detected w/ specific boundary.. Threat Score: 5.8/10 (MEDIUM). Confidence: 55%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 83%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack