πΊπΈ
mawan
2026-07-27 10:30:17
(23 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π©πͺ
Blexyel
2026-07-18 16:57:36
(1 week ago)
104.23.209.24 - - [18/Jul/2026:18:57:35 +0200] "GET /wp-content/wp-login.php HTTP/1.1" 404 146 "-" " ...
show more
104.23.209.24 - - [18/Jul/2026:18:57:35 +0200] "GET /wp-content/wp-login.php HTTP/1.1" 404 146 "-" "-"
...
show less
Brute-Force
Web App Attack
πΊπΈ
mawan
2026-07-04 20:43:50
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 11:40:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:40:20.344240 2026] [security2:error] [pid 29604:tid 29632] [client 104.23.209.24:11340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ilenefletcher.com.richardleeweatherman.com"] [uri "/.env.production"] [unique_id "agcGJHPfkU8KFolMT29B_AAAAYg"], referer: https://www.google.com/search?q=www.ilenefletcher.com.richardleeweatherman.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 11:06:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:05:53.231812 2026] [security2:error] [pid 25754:tid 25754] [client 104.23.209.24:13742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fourhillsco.grupoporvenir.com"] [uri "/.env.development.local"] [unique_id "agb-EUnj62VYpojCDxkBUgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 09:21:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:20:46.271320 2026] [security2:error] [pid 16754:tid 16754] [client 104.23.209.24:11934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hills-tax.com"] [uri "/.env.dev"] [unique_id "agblbtsNcTGWWrbPiVviuQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:35:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:31:58.367213 2026] [security2:error] [pid 25622:tid 25622] [client 104.23.209.24:10197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drinktopit.sendalawyerletter.com"] [uri "/.env.production"] [unique_id "agbZ_hKUDYl8fSXVc9a43gAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-05-14 22:05:49
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-13.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-05-09 15:31:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 11:31:50.207478 2026] [security2:error] [pid 22875:tid 22875] [client 104.23.209.24:11834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comparevision.com"] [uri "/.git/config"] [unique_id "af9TZu5gaQnwAmBXtQKYKQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-09 10:48:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 06:48:19.805856 2026] [security2:error] [pid 9692:tid 9692] [client 104.23.209.24:10627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "descolargtsv.com"] [uri "/.git/config"] [unique_id "af8Q8xEvKclSgE8nuazYbgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-04-21 22:06:00
(3 months ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
πΊπΈ
mnsf
2026-04-08 20:05:39
(3 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-04-05 14:05:09
(3 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-04-03 22:05:26
(3 months ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-22 12:34:24
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 08:34:18.402185 2026] [security2:error] [pid 32060:tid 32060] [client 104.23.209.24:13800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.natickvillagerentals.com"] [uri "/.env.production"] [unique_id "ab_hymPO4b6qurmyHrMGwQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack