Anonymous
2026-09-13 08:48:48
(9 hours ago)
104.23.217.102 - - [13/Sep/2026:08:48:47 +0000] "GET /wp-admin/install.php?step=1 HTTP/1.1" 503 5350 ...
show more
104.23.217.102 - - [13/Sep/2026:08:48:47 +0000] "GET /wp-admin/install.php?step=1 HTTP/1.1" 503 5350 "-" "http://ashleybutcher.net/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-08 16:21:16
(5 days ago)
tcp/443 (5 or more attempts)
Port Scan
๐จ๐ญ
ALPHANET
2026-09-02 03:17:59
(1 week ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐ฎ๐ช
Coolnagour
2026-09-01 23:06:04
(1 week ago)
funnypot web honeypot, port 80: GET http://funnypot.org/wp-admin/install.php
Web App Attack
๐ฎ๐ช
Coolnagour
2026-08-31 18:02:28
(1 week ago)
funnypot web honeypot, port 80: GET http://funnypot.org/wp-admin/install.php
Web App Attack
๐ฎ๐ช
Coolnagour
2026-08-30 12:03:55
(2 weeks ago)
funnypot web honeypot, port 80: GET http://funnypot.org/wp-admin/install.php
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-08-25 03:00:09
(2 weeks ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 06:42:46
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 02:42:40.453366 2026] [security2:error] [pid 29175:tid 29175] [client 104.23.217.102:13166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.artglass-jerusalem.net"] [uri "/.git/HEAD"] [unique_id "aoVQYFwCxPT_rwP4YCXBgwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 06:13:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 02:13:04.600732 2026] [security2:error] [pid 20198:tid 20198] [client 104.23.217.102:13318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.antech.net"] [uri "/.git/HEAD"] [unique_id "aoVJcNrxOXjONLsGt4pPqQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
kumiko
2026-08-19 04:44:00
(3 weeks ago)
[2026-08-19 07:44:00] Probing for dotfiles
"GET /.git/HEAD HTTP/2.0" 403
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 03:47:45
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 23:47:40.271247 2026] [security2:error] [pid 15490:tid 15490] [client 104.23.217.102:10533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cinemasky.net"] [uri "/.git/HEAD"] [unique_id "aoUnXC9X2SJMUS5jKRHpKgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 03:30:08
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 23:29:58.506546 2026] [security2:error] [pid 17648:tid 17648] [client 104.23.217.102:10201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.danasedge.net"] [uri "/.git/config"] [unique_id "aoUjNso9nnljXDybFMTgOgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-08-18 16:51:50
(3 weeks ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 21:28:27
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 17:28:21.886545 2026] [security2:error] [pid 2328:tid 2328] [client 104.23.217.102:10665] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tomweston.net"] [uri "/.git/HEAD"] [unique_id "aoN89WA5XvvZunPR9beCjAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:05:43
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:05:39.047580 2026] [security2:error] [pid 1526867:tid 1526867] [client 104.23.217.102:12187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jbtransportation.net"] [uri "/.git/config"] [unique_id "aoJ6g1FYyvSFyZrGQskHyQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack