๐ง๐ช
madeit
2026-09-23 22:17:55
(14 hours ago)
Web App Attack
๐ง๐ช
madeit
2026-09-07 17:04:32
(2 weeks ago)
Web App Attack
Anonymous
2026-08-18 05:37:39
(1 month ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 10:51:23
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:51:18.246160 2026] [security2:error] [pid 18204:tid 18204] [client 104.23.209.79:13511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.redlandssprinkler.com"] [uri "/.git/config"] [unique_id "aoLnpj9Ek-TqlL5V2hdU7QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:38:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:38:23.561405 2026] [security2:error] [pid 808:tid 808] [client 104.23.209.79:12769] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fulcrumusa.com"] [uri "/.git/HEAD"] [unique_id "aoKeTzy99g_jgrAQgkJyEAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:17:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:17:28.814835 2026] [security2:error] [pid 6525:tid 6525] [client 104.23.209.79:9750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "al-harbi.com"] [uri "/.git/config"] [unique_id "aoFV-OJeIBmLimmgXH8G8gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:59:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:59:29.305885 2026] [security2:error] [pid 27702:tid 27702] [client 104.23.209.79:10413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.zmgmt.com"] [uri "/.git/HEAD"] [unique_id "aoFRwZSwpbwB8s59ux6hJQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-16 05:28:48
(1 month ago)
[SunAug1607:28:44.5347392026][security2:error][pid1607923:tid1607959][client104.23.209.79:0]ModSecur ...
show more
[SunAug1607:28:44.5347392026][security2:error][pid1607923:tid1607959][client104.23.209.79:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"465\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.ticino-host.ch.hosting-domini.ch\"][uri\"/.git/HEAD\"][unique_id\"aoFKjEgA9SDw2_tiWGhJNQAAAVM\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 22:28:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 18:27:52.309799 2026] [security2:error] [pid 9915:tid 9915] [client 104.23.209.79:14187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.batesstrategygroup.com"] [uri "/.git/config"] [unique_id "an5E6BlTYYfLFv1E5PQdQwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 04:01:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 00:01:27.358679 2026] [security2:error] [pid 2827854:tid 2827854] [client 104.23.209.79:13288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thinkingepic.com"] [uri "/.git/HEAD"] [unique_id "anqel1IKz_r21-KSEJNiUwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 11:06:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:05:18.342256 2026] [security2:error] [pid 29012:tid 29012] [client 104.23.209.79:14323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "san-marino-boat-registration.com"] [uri "/.env.development.local"] [unique_id "agb97h6hRA5XnlYvOB-7DwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-05-13 09:10:21
(4 months ago)
๐จ Recon detected (nft drop)
SRC=104.23.209.79
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=104.23.209.79
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฆ๐บ
oncord
2026-04-14 07:27:19
(5 months ago)
Form spam
Web Spam
๐บ๐ธ
mnsf
2026-04-05 12:05:32
(5 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
Anonymous
2026-04-03 07:45:26
(5 months ago)
104.23.209.79 - - [03/Apr/2026:09:43:55 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
104.23.209.79 - - [03/Apr/2026:09:43:55 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.0" 404 460 "-" "-"
104.23.209.79 - - [03/Apr/2026:09:43:55 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 246 "-" "-"
104.23.209.79 - - [03/Apr/2026:09:45:25 +0200] "GET /wp-includes/js/wp-login.php HTTP/1.0" 404 460 "-" "-"
104.23.209.79 - - [03/Apr/2026:09:45:25 +0200] "GET /wp-includes/js/wp-login.php HTTP/1.1" 404 246 "-" "-"
104.23.209.79 - - [03/Apr/2026:09:45:25 +0200] "GET /wp-includes/Text/network.php HTTP/1.0" 404 460 "-" "-"
...
show less
Brute-Force
Web App Attack