๐บ๐ธ
johnkarlhill
2026-09-07 01:30:10
(1 week ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
๐บ๐ธ
jbettigole
2026-08-29 06:20:49
(2 weeks ago)
MikroTik RouterOS: repeated connection attempts against non-public admin/service ports (SSH/Telnet/F ...
show more
MikroTik RouterOS: repeated connection attempts against non-public admin/service ports (SSH/Telnet/FTP/Winbox/API/WWW) triggering escalating 5m/15m/1h/1d blacklist
show less
Brute-Force
Hacking
๐บ๐ธ
CBJ
2026-08-23 09:22:01
(3 weeks ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 22:44:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:44:25.430917 2026] [security2:error] [pid 13924:tid 13924] [client 104.23.211.59:9461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.valkyriepanthers.com"] [uri "/.git/HEAD"] [unique_id "aoOOyex4-WwlpFLs48cF1gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 12:13:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:13:10.366690 2026] [security2:error] [pid 16053:tid 16053] [client 104.23.211.59:11469] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kathleenhazlett.com"] [uri "/.git/HEAD"] [unique_id "aoL61pOC0Y_SVvsQ3Srr6wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 11:01:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:01:27.572779 2026] [security2:error] [pid 11340:tid 11340] [client 104.23.211.59:9217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.johnatuttle.us"] [uri "/.git/config"] [unique_id "aoLqBwKRT8iuMrvkobUYwAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:53:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:52:53.113474 2026] [security2:error] [pid 8004:tid 8004] [client 104.23.211.59:12292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.qed-consulting.co"] [uri "/.git/config"] [unique_id "aoKhtdYJ_P-9gkQEuJ969QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 04:46:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:46:04.869874 2026] [security2:error] [pid 6246:tid 6246] [client 104.23.211.59:10324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nashuaboyscouts.org"] [uri "/.git/HEAD"] [unique_id "aoKSDG-BdP3Gwd1dfdrQdgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:30:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:30:33.159519 2026] [security2:error] [pid 12788:tid 12788] [client 104.23.211.59:13021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buygoldandsilveratspot.mroxygen.org"] [uri "/.git/HEAD"] [unique_id "aoF1KcUZwPZCWYqPnQpY_AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:08:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:07:59.754153 2026] [security2:error] [pid 10968:tid 11020] [client 104.23.211.59:11483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ecocentri.city"] [uri "/.git/HEAD"] [unique_id "aoEpj4PXAgXmTDL-BACdwQAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 11:23:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 07:23:52.392302 2026] [security2:error] [pid 3050206:tid 3050206] [client 104.23.211.59:13208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intnlc.org"] [uri "/.git/HEAD"] [unique_id "an2pSNuAdUwni0cl2021DQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-09 19:22:28
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 10:04:57
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 06:04:46.628257 2026] [security2:error] [pid 29814:tid 29814] [client 104.23.211.59:12970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bvnboysbasketball.com"] [uri "/.env.production"] [unique_id "agbvvtj7NLaYLhEu6isOswAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 08:43:21
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 04:43:15.986137 2026] [security2:error] [pid 20015:tid 20015] [client 104.23.211.59:11987] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aim-controls.com"] [uri "/.git/config"] [unique_id "agBFI-qwadPy4pNRey04cAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-07 06:06:01
(5 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack