๐ฉ๐ช
ghostwarriors
2026-08-21 10:50:14
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-21 10:46:38
(5 days ago)
104.23.209.133 - - [21/Aug/2026:12:46:33 +0200] "GET /this_is_a_new_hello_world.php HTTP/2.0" 404 34 ...
show more
104.23.209.133 - - [21/Aug/2026:12:46:33 +0200] "GET /this_is_a_new_hello_world.php HTTP/2.0" 404 341 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:33 +0200] "GET //wp-includes/l10n/themes.php HTTP/2.0" 404 311 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:33 +0200] "GET //shell.php HTTP/2.0" 404 55 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:33 +0200] "GET /wp-blog-header.php HTTP/2.0" 404 55 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:34 +0200] "GET /file5.php HTTP/2.0" 404 78 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:34 +0200] "GET //ops.php HTTP/2.0" 404 55 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:34 +0200] "GET //wp-file.php HTTP/2.0" 404 55 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:34 +0200] "GET /ops.php HTTP/2.0" 404 55 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:35 +0200] "GET /kk.php HTTP/2.0" 404 78 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:35 +0200] "GET /1.php HTTP/2.0" 404 55 "-" "-"
104.23.209.133 - - [21/Aug/2026:12:46:35 +0200] "GET /wp-sing.php
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-17 22:58:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:58:16.827294 2026] [security2:error] [pid 12204:tid 12204] [client 104.23.209.133:12669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vabq.com"] [uri "/.git/HEAD"] [unique_id "aoOSCO0lL7SS8OkxLtcYYAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-06 03:46:24
(2 weeks ago)
Web App Attack
๐บ๐ธ
mawan
2026-07-31 21:43:38
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
abdubhai
2026-07-07 09:01:48
(1 month ago)
104.23.209.133 - - [07/Jul/2026:
...
Brute-Force
๐ฒ๐ฝ
octageeks.com
2026-07-03 04:17:48
(1 month ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-01 04:10:27
(1 month ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
mnsf
2026-04-07 08:05:29
(4 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 05:49:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 01:49:40.503871 2026] [security2:error] [pid 15879:tid 15879] [client 104.23.209.133:12570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cmcgroup.us.com"] [uri "/.env2"] [unique_id "ab4xdGqbEvJW-y-6ytLTBAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:06:23
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:06:16.864546 2026] [security2:error] [pid 12289:tid 12289] [client 104.23.209.133:9270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dodojuice.com"] [uri "/.env.docker"] [unique_id "ab39GKoP0g-hj4gXBHUL1AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:16:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:16:28.185555 2026] [security2:error] [pid 5796:tid 5796] [client 104.23.209.133:11640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.virttee.com"] [uri "/.env"] [unique_id "ab3xbLZSqAi21dR33ofiHwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:15:41
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:15:38.124433 2026] [security2:error] [pid 3236:tid 3236] [client 104.23.209.133:14299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkalleyproductions.com"] [uri "/app/.env"] [unique_id "ab3jKuQKPCctsDrg99Cn0AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
drewf.ink
2026-03-17 03:07:45
(5 months ago)
[03:07] Port scanning. Port(s) scanned: TCP/8443
Port Scan
Anonymous
2025-12-29 08:00:28
(7 months ago)
[Mon Dec 29 08:58:40.786204 2025] [authz_core:error] [pid 26597] [client 104.23.209.133:10454] AH016 ...
show more
[Mon Dec 29 08:58:40.786204 2025] [authz_core:error] [pid 26597] [client 104.23.209.133:10454] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Dec 29 08:58:41.144563 2025] [authz_core:error] [pid 26597] [client 104.23.209.133:10454] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Dec 29 09:00:27.284522 2025] [authz_core:error] [pid 27202] [client 104.23.209.133:10134] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack