๐ง๐ช
madeit
2026-08-31 01:13:44
(1 day ago)
Web App Attack
๐บ๐ธ
mawan
2026-08-21 22:39:21
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-08-20 16:51:21
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-18 21:59:33
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-18
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-18 03:08:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 23:08:01.605684 2026] [security2:error] [pid 30176:tid 30176] [client 104.23.209.41:12404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.boat-registration-croatia.com"] [uri "/.git/HEAD"] [unique_id "aoPMkazO1sVZsLfso5UN5gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-17 01:19:06
(2 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mnsf
2026-04-08 21:06:04
(4 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 03:06:16
(4 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 17:21:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 13:21:46.072083 2026] [security2:error] [pid 12195:tid 12195] [client 104.23.209.41:10957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cabrynpoodles.com"] [uri "/.env.staging"] [unique_id "acAlKmRyxF6BPyrb-gK3IgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-03-21 17:59:52
(5 months ago)
2026/03/21 17:59:52 [error] 2491775#2491775: *181262 access forbidden by rule, client: 104.23.209.41 ...
show more
2026/03/21 17:59:52 [error] 2491775#2491775: *181262 access forbidden by rule, client: 104.23.209.41, server: job-search-api.bridginggaps.tech, request: "GET /.git/refs/heads/main HTTP/2.0", host: "job-search-api.bridginggaps.tech"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 15:11:43
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 11:11:24.929494 2026] [security2:error] [pid 29330:tid 29330] [client 104.23.209.41:10487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.henrietteg.com"] [uri "/backend/.env"] [unique_id "ab61HM55kYRJ8-MSbnthhAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:53:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:53:03.905963 2026] [security2:error] [pid 13256:tid 13256] [client 104.23.209.41:13137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ozarktulsa.com"] [uri "/.env.save"] [unique_id "ab4kL2DPtrDcaGCNXeWcqwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:35:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:34:54.124485 2026] [security2:error] [pid 25178:tid 25178] [client 104.23.209.41:13807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.givemethemic.com"] [uri "/.env.development"] [unique_id "ab4f7tKJgwpnQWzHZrpFqQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:17:23
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:17:03.966079 2026] [security2:error] [pid 29112:tid 29112] [client 104.23.209.41:13382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.noxiousthoughts.com"] [uri "/config/.env"] [unique_id "ab4bv0CQSxQIYn0Eo4xgvwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:06:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:06:31.359912 2026] [security2:error] [pid 12937:tid 12937] [client 104.23.209.41:13024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.clearlakelots.com"] [uri "/.env.development.local"] [unique_id "ab39J6I4GvaHAPZpxN63kQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack