Anonymous
2026-08-28 08:34:21
(1 day ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
CBJ
2026-08-23 09:22:18
(6 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 13:26:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:26:21.950691 2026] [security2:error] [pid 17114:tid 17114] [client 104.23.209.146:9401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scienceandpoetrywithgrandpa.xyz"] [uri "/.env.local"] [unique_id "aomjfUO6mdeSDkemqCaVswAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-21 10:50:13
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-21 10:46:39
(1 week ago)
104.23.209.146 - - [21/Aug/2026:12:46:34 +0200] "GET /classwithtostring.php HTTP/2.0" 404 55 "-" "-" ...
show more
104.23.209.146 - - [21/Aug/2026:12:46:34 +0200] "GET /classwithtostring.php HTTP/2.0" 404 55 "-" "-"
104.23.209.146 - - [21/Aug/2026:08:16:13 +0200] "GET /wp-json/ HTTP/2.0" 404 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
104.23.209.146 - - [21/Aug/2026:12:46:32 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/2.0" 404 357 "-" "-"
104.23.209.146 - - [21/Aug/2026:12:46:33 +0200] "GET /wp-content/plugins/about.php HTTP/2.0" 404 312 "-" "-"
104.23.209.146 - - [21/Aug/2026:12:46:33 +0200] "GET /wp-includes/wp-class.php HTTP/2.0" 404 289 "-" "-"
104.23.209.146 - - [21/Aug/2026:12:46:34 +0200] "GET //item.php HTTP/2.0" 404 318 "-" "-"
104.23.209.146 - - [21/Aug/2026:12:46:34 +0200] "GET /readme.php HTTP/2.0" 404 55 "-" "-"
104.23.209.146 - - [21/Aug/2026:12:46:34 +0200] "GET /wp-content/themes/admin.php HTTP/2.0" 404 289 "-" "-"
104.23.209.146 - - [21/Aug/2026:12:46:35 +0200] "GET /wp-the.php HTTP
show less
Web App Attack
Brute-Force
๐ง๐ฌ
Stoyko Stoykov
2026-08-18 23:03:11
(1 week ago)
104.23.209.146 - - [19/Aug/2026:02:03:11 +0300] "GET /wp-includes/php-compat/Olu2RK.php HTTP/2.0" 40 ...
show more
104.23.209.146 - - [19/Aug/2026:02:03:11 +0300] "GET /wp-includes/php-compat/Olu2RK.php HTTP/2.0" 404 1852 "-" "-"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 12:46:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:46:15.342902 2026] [security2:error] [pid 15255:tid 15270] [client 104.23.209.146:9747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.certifiedfinancialanalyst.org"] [uri "/.git/config"] [unique_id "aoMClwyzmVfedpI_e-8eywAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:10:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:09:59.744316 2026] [security2:error] [pid 29286:tid 29286] [client 104.23.209.146:12566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ocmtx.org"] [uri "/.git/config"] [unique_id "aoLP56Vkeeo3p8fINax15AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-16 11:50:07
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-16 11:37:00
(1 week ago)
104.23.209.146 - - [16/Aug/2026:13:36:56 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
104.23.209.146 - - [16/Aug/2026:13:36:56 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/2.0" 404 357 "-" "-"
104.23.209.146 - - [16/Aug/2026:13:36:57 +0200] "GET /ws61.php HTTP/2.0" 404 318 "-" "-"
104.23.209.146 - - [16/Aug/2026:13:36:57 +0200] "GET /ze.php HTTP/2.0" 404 55 "-" "-"
104.23.209.146 - - [16/Aug/2026:13:36:57 +0200] "GET /new4.php HTTP/2.0" 404 55 "-" "-"
104.23.209.146 - - [16/Aug/2026:13:36:57 +0200] "GET /grsiuk.php HTTP/2.0" 404 55 "-" "-"
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-16 09:57:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 05:57:33.825686 2026] [security2:error] [pid 30952:tid 30975] [client 104.23.209.146:11298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.coloradosellers.com"] [uri "/.git/HEAD"] [unique_id "aoGJjSXYt94a243V7P8q3AAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:02:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:01:56.329705 2026] [security2:error] [pid 27934:tid 27934] [client 104.23.209.146:13850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.haroparquet.com"] [uri "/.git/HEAD"] [unique_id "aoFERFUpDZFg8_OExmKhDgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:14:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:14:42.688456 2026] [security2:error] [pid 11836:tid 11836] [client 104.23.209.146:9872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.danzadance.org"] [uri "/.git/config"] [unique_id "aoErInlkpJcCaSeifgOt4wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 00:59:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 20:59:00.596520 2026] [security2:error] [pid 5015:tid 5015] [client 104.23.209.146:10897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michaeltenore.com"] [uri "/.git/config"] [unique_id "aoELVKBZmBGy7tCQfACTxAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 22:54:23
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 18:54:18.257742 2026] [security2:error] [pid 16576:tid 16576] [client 104.23.209.146:11343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clcmillvale.com"] [uri "/.git/HEAD"] [unique_id "an-cmpOH_GepOYrx232JKAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack