๐ท๐บ
DZBOT
2026-06-09 03:01:52
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 01:57:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:57:14.993278 2026] [security2:error] [pid 10497:tid 10497] [client 104.23.217.10:10979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "authorsfoundry.pellman-world.com"] [uri "/.git/config"] [unique_id "aidy-vjeO-6Fg6lTEeNvSwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 17:40:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:40:16.251818 2026] [security2:error] [pid 7302:tid 7304] [client 104.23.217.10:11849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/.git/config"] [unique_id "aib-gOEUDot_8pf-SRvu_QAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 10:17:09
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 06:17:01.842733 2026] [security2:error] [pid 32042:tid 32042] [client 104.23.217.10:11474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m.yeswecanhandyservices.com"] [uri "/.git/config"] [unique_id "ahAtHaeN4flrdbJbDFd4SAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-16 21:59:48
(1 month ago)
Auto-ban: >3000 req/min op 2026-05-16
Web App Attack
SSH
Hacking
๐บ๐ธ
xxkodedxx
2026-05-13 07:39:58
(1 month ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: SE / AS13335 Cloudflare, Inc.
Active: 07:39:38 UTC
Volume: 1 HTTP req
Probed: /wp-admin/install.php?step=1
Status mix: 444ร1
UA: "http://zvxlabs.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 19:35:46
(1 month ago)
(caddyscan) Scanner path probe from 104.23.217.10 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.23.217.10 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.217.10 - - [12/May/2026:19:33:13 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.217.10 - - [12/May/2026:19:33:45 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.217.10 - - [12/May/2026:19:33:50 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.217.10 - - [12/May/2026:19:35:35 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.217.10 - - [12/May/2026:19:35:37 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
chrisj
2026-04-29 20:46:28
(1 month ago)
[Wed Apr 29 20:46:21.033305 2026] [proxy_fcgi:error] [pid 672030:tid 672030] [client 104.23.217.10:1 ...
show more
[Wed Apr 29 20:46:21.033305 2026] [proxy_fcgi:error] [pid 672030:tid 672030] [client 104.23.217.10:10913] AH01071: Got error 'Primary script unknown'
[Wed Apr 29 20:46:28.038740 2026] [proxy_fcgi:error] [pid 671971:tid 671971] [client 104.23.217.10:13271] AH01071: Got error 'Primary script unknown'
[Wed Apr 29 20:46:28.199465 2026] [proxy_fcgi:error] [pid 671971:tid 671971] [client 104.23.217.10:13271] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ณ๐ฑ
wolfemium
2026-03-02 01:13:44
(3 months ago)
104.23.217.10 - - [02/Mar/2026:03:13:42 +0200] "GET /mga.php HTTP/1.1" 502 150 "-" "-"
104.23.217.10 ...
show more
104.23.217.10 - - [02/Mar/2026:03:13:42 +0200] "GET /mga.php HTTP/1.1" 502 150 "-" "-"
104.23.217.10 - - [02/Mar/2026:03:13:43 +0200] "GET /maxro.php HTTP/1.1" 502 150 "-" "-"
104.23.217.10 - - [02/Mar/2026:03:13:43 +0200] "GET /agg.php HTTP/1.1" 502 150 "-" "-"
104.23.217.10 - - [02/Mar/2026:03:13:43 +0200] "GET /pass4.php HTTP/1.1" 502 150 "-" "-"
104.23.217.10 - - [02/Mar/2026:03:13:43 +0200] "GET /wsws.php HTTP/1.1" 502 150 "-" "-"
104.23.217.10 - - [02/Mar/2026:03:13:43 +0200] "GET /G-in.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐ฉ๐ช
ps-center
2026-02-23 23:19:58
(3 months ago)
MYH: Web Attack GET /wordpress/wp-admin/setup-config.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2025-11-24 15:09:10
(6 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2025-09-12 05:46:17
(9 months ago)
[Fri Sep 12 07:46:13.993250 2025] [authz_core:error] [pid 26279] [client 104.23.217.10:48886] AH0163 ...
show more
[Fri Sep 12 07:46:13.993250 2025] [authz_core:error] [pid 26279] [client 104.23.217.10:48886] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Sep 12 07:46:16.797637 2025] [authz_core:error] [pid 26279] [client 104.23.217.10:48886] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Sep 12 07:46:17.156403 2025] [authz_core:error] [pid 26279] [client 104.23.217.10:48886] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฆ๐บ
weblite
2025-09-10 08:01:19
(9 months ago)
WP_EXPLOIT_PROBE WP_MALWARE_PROBE
Hacking
Web App Attack
Anonymous
2025-09-09 00:20:13
(9 months ago)
[Tue Sep 09 02:20:12.449399 2025] [authz_core:error] [pid 16810] [client 104.23.217.10:32184] AH0163 ...
show more
[Tue Sep 09 02:20:12.449399 2025] [authz_core:error] [pid 16810] [client 104.23.217.10:32184] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 09 02:20:12.479417 2025] [authz_core:error] [pid 16810] [client 104.23.217.10:32184] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 09 02:20:12.510193 2025] [authz_core:error] [pid 16810] [client 104.23.217.10:32184] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฆ๐บ
weblite
2025-09-06 15:20:16
(9 months ago)
WP_EXPLOIT_PROBE WP_MALWARE_PROBE
Hacking
Web App Attack