Anonymous
2026-10-08 02:12:31
(2 days ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ท๐ด
DamonOne
2026-10-04 21:41:28
(5 days ago)
Blocked by OPNsense; 16 hits, proto=tcp, ports=8080
Port Scan
Hacking
Anonymous
2026-09-30 11:47:22
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-29 08:44:25
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-18 23:34:45
(3 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-09-08 02:25:34
(1 month ago)
Web App Attack
๐ฉ๐ช
lolyay
2026-09-06 04:04:12
(1 month ago)
104.23.213.160 - - [06/Sep/2026:04:04:10 +0000] "GET /.git/config HTTP/1.1" 200 4 "-" "Mozilla/5.0 ( ...
show more
104.23.213.160 - - [06/Sep/2026:04:04:10 +0000] "GET /.git/config HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.213.160 - - [06/Sep/2026:04:04:10 +0000] "GET /.env HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
๐ง๐ช
madeit
2026-08-28 20:14:03
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:46:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:46:14.970160 2026] [security2:error] [pid 7019:tid 7019] [client 104.23.213.160:9629] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.m2oblivion.com"] [uri "/.git/HEAD"] [unique_id "aoKgJg6WrgFRzvex1LyqwwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-16 22:59:45
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:02:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:01:56.064372 2026] [security2:error] [pid 22630:tid 22630] [client 104.23.213.160:13811] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.deubellzebub.com"] [uri "/.git/config"] [unique_id "aoFERHbVixtLqj9N0RigzgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
joharikop
2026-08-13 14:43:28
(1 month ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 21:35:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 17:35:46.633055 2026] [security2:error] [pid 2663791:tid 2663791] [client 104.23.213.160:11857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.restaurantfixture.com"] [uri "/.git/HEAD"] [unique_id "anuVso1YJRpvI5YuDVGksQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 15:42:16
(2 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-07-04 12:35:06
(3 months ago)
104.23.213.160 - - [04/Jul/2026:14:34:37 +0200] "GET /?h=9419666581100 HTTP/1.1" 403 12583 "-" "Mozi ...
show more
104.23.213.160 - - [04/Jul/2026:14:34:37 +0200] "GET /?h=9419666581100 HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.7871.46 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
104.23.213.160 - - [04/Jul/2026:14:34:39 +0200] "GET /?h=29574383461100 HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.7871.46 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
104.23.213.160 - - [04/Jul/2026:14:34:39 +0200] "GET /?shop/sold?id=top29767548421100 HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.7871.46 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
104.23.213.160 - - [04/Jul/2026:14:34:41 +0200] "GET /?productSearch/pictureSearch?id=2971440
...
show less
Bad Web Bot
Web App Attack