Anonymous
2026-09-06 13:21:22
(5 hours ago)
104.23.209.71 - - [06/Sep/2026:15:21:18 +0200] "GET /.aws/credentials HTTP/1.1" 403 124 "-" "curl/8. ...
show more
104.23.209.71 - - [06/Sep/2026:15:21:18 +0200] "GET /.aws/credentials HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:18 +0200] "GET /.aws/.config/.smtp_config.bak HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:18 +0200] "GET /config/mail.php HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:18 +0200] "GET /.gitkeep HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:18 +0200] "GET /.env.tmp HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:18 +0200] "GET /phpmailer_config.php HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:18 +0200] "GET /aws_keys_backup.json HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:19 +0200] "GET /config/aws-keys.json HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:19 +0200] "GET /smtp/aws-credentials.yml HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.209.71 - - [06/Sep/2026:15:21:19
...
show less
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-09-04 11:08:34
(2 days ago)
Web App Attack
Anonymous
2026-08-31 10:59:20
(6 days ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 08:32:27
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:32:20.681765 2026] [security2:error] [pid 31920:tid 31920] [client 104.23.209.71:11141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lawrencehale.com"] [uri "/.git/config"] [unique_id "aoLHFHvd8rTYMZ3bwOMBjQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 08:06:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:06:42.079337 2026] [security2:error] [pid 4296:tid 4296] [client 104.23.209.71:11018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.unicomtechnologies.com"] [uri "/.git/config"] [unique_id "aoFvkrVaCJKRPN7rGVzqCgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 07:02:36
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:02:30.949915 2026] [security2:error] [pid 29187:tid 29187] [client 104.23.209.71:13295] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.amaia.biz"] [uri "/.git/HEAD"] [unique_id "aoFghkF9bBRKXJsuQHDHZwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-16 02:37:31
(3 weeks ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-15 03:23:19
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 23:23:10.691389 2026] [security2:error] [pid 5811:tid 5865] [client 104.23.209.71:11288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ardentsi.com"] [uri "/.git/config"] [unique_id "an_bnlQNnGmM3BD1M8s7KQAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-13 20:21:13
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π§πͺ
madeit
2026-08-13 10:50:15
(3 weeks ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-12 10:10:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 06:10:16.845845 2026] [security2:error] [pid 12531:tid 12531] [client 104.23.209.71:9939] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wedemandavote.com"] [uri "/.git/HEAD"] [unique_id "anxGiNNmXwD4UDNHbpHLqQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 02:29:28
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 22:29:19.999404 2026] [security2:error] [pid 966120:tid 966120] [client 104.23.209.71:12967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.neff.family.name"] [uri "/.git/HEAD"] [unique_id "anqI_2I0CdzJXnt3RV_LBwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 02:13:40
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 22:13:32.741858 2026] [security2:error] [pid 1324020:tid 1324047] [client 104.23.209.71:11228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.garyanddani.guitarmans.com"] [uri "/.git/config"] [unique_id "anqFTPLaSCXRvxi0KZ37MgAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
abdubhai
2026-07-28 03:01:46
(1 month ago)
104.23.209.71 - - [28/Jul/2026:0
...
Brute-Force
Anonymous
2026-07-27 09:16:52
(1 month ago)
104.23.209.71 - - [27/Jul/2026:11:16:52 +0200] "GET /control-panel/.env HTTP/1.1" 403 183 "-" "Mozil ...
show more
104.23.209.71 - - [27/Jul/2026:11:16:52 +0200] "GET /control-panel/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.209.71 - - [27/Jul/2026:11:16:52 +0200] "GET /user-panel/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.209.71 - - [27/Jul/2026:11:16:52 +0200] "GET /node/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.209.71 - - [27/Jul/2026:11:16:52 +0200] "GET /express/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.209.71 - - [27/Jul/2026:11:16:52 +0200] "GET /next/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.209.71 - - [27/Jul/2026:11:16:
...
show less
Bad Web Bot
Web App Attack