๐บ๐ธ
johnkarlhill
2026-09-16 10:27:34
(4 days ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
Anonymous
2026-09-12 20:12:46
(1 week ago)
[Sat Sep 12 22:12:43.750213 2026] [authz_core:error] [pid 32401] [client 104.23.190.49:10346] AH0163 ...
show more
[Sat Sep 12 22:12:43.750213 2026] [authz_core:error] [pid 32401] [client 104.23.190.49:10346] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Sep 12 22:12:44.004312 2026] [authz_core:error] [pid 32401] [client 104.23.190.49:10346] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Sep 12 22:12:45.453054 2026] [authz_core:error] [pid 32401] [client 104.23.190.49:10346] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2026-07-17 12:24:56
(2 months ago)
UFW:High-frequency access to unused ports
Port Scan
๐ณ๐ด
jad-abuse
2026-07-04 02:36:25
(2 months ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: source_ba ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: source_backup. Observed by 1 sensor(s); 1 hits.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ValtonTahiri
2026-07-02 13:54:50
(2 months ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=104.23.190.49; proto=TCP; source_port=12408; target_port=8443; flags=SYN
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-15 08:21:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 04:21:27.623393 2026] [security2:error] [pid 2638:tid 2638] [client 104.23.190.49:10663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clustershow.com"] [uri "/.env.local"] [unique_id "ai-2B3xDXH_v7k4OPgQc7AAAAAQ"], referer: https://www.google.com/search?q=clustershow.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-06-01 22:33:22
(3 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /admin/.env S ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /admin/.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
abdubhai
2026-05-15 00:25:50
(4 months ago)
104.23.190.49 - - [15/May/2026:0
...
Brute-Force
Anonymous
2026-05-06 16:40:13
(4 months ago)
[Wed May 06 18:40:12.415631 2026] [authz_core:error] [pid 12444] [client 104.23.190.49:12662] AH0163 ...
show more
[Wed May 06 18:40:12.415631 2026] [authz_core:error] [pid 12444] [client 104.23.190.49:12662] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed May 06 18:40:12.577392 2026] [authz_core:error] [pid 12444] [client 104.23.190.49:12662] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed May 06 18:40:12.712632 2026] [authz_core:error] [pid 12444] [client 104.23.190.49:12662] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-08 20:14:09
(5 months ago)
[Wed Apr 08 22:14:09.158533 2026] [authz_core:error] [pid 8106] [client 104.23.190.49:10858] AH01630 ...
show more
[Wed Apr 08 22:14:09.158533 2026] [authz_core:error] [pid 8106] [client 104.23.190.49:10858] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Apr 08 22:14:09.314488 2026] [authz_core:error] [pid 8106] [client 104.23.190.49:10858] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Apr 08 22:14:09.437750 2026] [authz_core:error] [pid 8106] [client 104.23.190.49:10858] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 19:24:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 15:24:32.984500 2026] [security2:error] [pid 295291:tid 295291] [client 104.23.190.49:10658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puckerbackbikinis.puckerbikini.com"] [uri "/private/.env"] [unique_id "adQIcOrwEoRPsdPTI-ngfgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 12:12:59
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 08:12:46.267634 2026] [security2:error] [pid 8850:tid 8850] [client 104.23.190.49:11260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.whipchecks.com.au"] [uri "/.env.backup"] [unique_id "ac-uvjVmI217Wvxjl925MgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-03-20 16:44:16
(5 months ago)
2026/03/20 16:44:15 [error] 2491776#2491776: *167752 access forbidden by rule, client: 104.23.190.49 ...
show more
2026/03/20 16:44:15 [error] 2491776#2491776: *167752 access forbidden by rule, client: 104.23.190.49, server: wynnesmiles.bridginggaps.tech, request: "GET /.git/index HTTP/2.0", host: "wynnesmiles.bridginggaps.tech"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 08:44:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:44:31.803555 2026] [security2:error] [pid 29701:tid 29701] [client 104.23.190.49:12337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.offbeatcompassion.com"] [uri "/.env.container"] [unique_id "abu3b3v_NPdkOcbuxOv3fwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 08:27:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.190.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:27:12.624457 2026] [security2:error] [pid 8796:tid 8912] [client 104.23.190.49:12643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.andestravel.net"] [uri "/.env.local.backup"] [unique_id "abuzYLy4sDyDw0ttnuR6UAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack