๐บ๐ธ
mawan
2026-07-27 12:25:25
(1 day ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mnsf
2026-03-25 17:05:29
(4 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 16:28:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 12:28:26.310147 2026] [security2:error] [pid 25792:tid 25792] [client 104.23.209.84:9569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.new-bethel-baptist-church.com"] [uri "/config/.env.local"] [unique_id "acAYqgaflSDUP8U9V_B2iQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 12:37:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 08:37:36.024381 2026] [security2:error] [pid 6417:tid 6417] [client 104.23.209.84:13330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.natickvillagerentals.com"] [uri "/.env.dist"] [unique_id "ab_ikAz6tUSGZ2K5HNyMgQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:27:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:27:44.355031 2026] [security2:error] [pid 6667:tid 6667] [client 104.23.209.84:9843] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kinderland-preschool.com"] [uri "/.env_secret"] [unique_id "ab4CII0N8zHWTlDbiGCEeAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:06:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:05:54.943864 2026] [security2:error] [pid 9974:tid 9974] [client 104.23.209.84:13913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dodojuice.com"] [uri "/.env.dev"] [unique_id "ab39AsTaYJBh1lprvkLGDgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:21:48
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:21:43.746232 2026] [security2:error] [pid 21828:tid 21828] [client 104.23.209.84:14302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.arabou.co"] [uri "/root/.env"] [unique_id "ab3yp4PpvIK2ROln6-kdTgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-29 08:00:18
(6 months ago)
[Mon Dec 29 09:00:10.226088 2025] [authz_core:error] [pid 26594] [client 104.23.209.84:9723] AH01630 ...
show more
[Mon Dec 29 09:00:10.226088 2025] [authz_core:error] [pid 26594] [client 104.23.209.84:9723] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Dec 29 09:00:11.055487 2025] [authz_core:error] [pid 26594] [client 104.23.209.84:9723] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Dec 29 09:00:13.176972 2025] [authz_core:error] [pid 26594] [client 104.23.209.84:9723] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฉ๐ช
Blexyel
2025-10-22 08:58:54
(9 months ago)
104.23.209.84 - - [22/Oct/2025:08:58:51 +0000] "GET /.git/config HTTP/1.1" 200 2116 "-" "Mozilla/5.0 ...
show more
104.23.209.84 - - [22/Oct/2025:08:58:51 +0000] "GET /.git/config HTTP/1.1" 200 2116 "-" "Mozilla/5.0"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
sterile.network
2025-10-05 19:16:22
(9 months ago)
Blocked by UFW on ropanel1 [80/tcp]
Source port: 49126
TTL: 46
Packet length: 60
TOS: 0x00
Port Scan
Web App Attack
Anonymous
2025-08-21 04:57:07
(11 months ago)
wp admin page access attempt
...
Hacking
Web App Attack
Anonymous
2025-08-19 02:48:38
(11 months ago)
wp admin page access attempt
...
Hacking
Web App Attack
๐ฉ๐ช
ps-center
2025-07-24 11:24:29
(1 year ago)
SS1: Web Attack GET /wp-includes/widgets/mar.php
GET /wp-includes/manager.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2025-07-23 02:18:53
(1 year ago)
SS1: Web Attack GET /wp-includes/images/wp-login.php
GET /wp-includes/blocks/wp-conflg.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2025-07-05 01:21:44
(1 year ago)
104.23.209.84 - - [05/Jul/2025:03:21:44 +0200] "GET /.git/config HTTP/2.0" 400 313 "-" "ct\xE2\x80\x ...
show more
104.23.209.84 - - [05/Jul/2025:03:21:44 +0200] "GET /.git/config HTTP/2.0" 400 313 "-" "ct\xE2\x80\x91git\xE2\x80\x91scanner/0.4"
...
show less
Brute-Force
Web App Attack