πΊπΈ
TPI-Abuse
2026-08-17 15:59:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 11:59:01.064903 2026] [security2:error] [pid 1683:tid 1739] [client 104.23.221.10:12847] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almerirock.com.emehache.net"] [uri "/.git/HEAD"] [unique_id "aoMvxSxDZiwUBNkvmuocYgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TIScore
2026-08-17 15:28:40
(3 hours ago)
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path ...
show more
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path. Last path: /wp-admin/install.php
show less
Web App Attack
πΊπΈ
craudiovizai
2026-08-17 12:30:31
(6 hours ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-17 08:54:29
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:54:21.931192 2026] [security2:error] [pid 22891:tid 22891] [client 104.23.221.10:10609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vrevgaming.net"] [uri "/.git/config"] [unique_id "aoLMPUNarinLQ6HBKCnr0gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 01:51:55
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:51:48.621611 2026] [security2:error] [pid 442:tid 442] [client 104.23.221.10:11461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mjsom.afjm.net"] [uri "/.git/HEAD"] [unique_id "aoJpNADnOrqjZr5A8JffbwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 23:42:09
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:42:04.944089 2026] [security2:error] [pid 7860:tid 7860] [client 104.23.221.10:12023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trasimeno.montepulciano.org"] [uri "/.git/config"] [unique_id "aoJKzMi8JGASPJIknzz7ZwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 22:58:48
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:58:41.345855 2026] [security2:error] [pid 13057:tid 13057] [client 104.23.221.10:10756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stuartpearson.net"] [uri "/.git/HEAD"] [unique_id "aoJAoTRoPwwlbOzfCA7j6QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TIScore
2026-08-16 15:28:34
(1 day ago)
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path ...
show more
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path. Last path: /wp-admin/install.php
show less
Web App Attack
πΊπΈ
TIScore
2026-08-15 15:28:29
(2 days ago)
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path ...
show more
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path. Last path: /wp-admin/install.php
show less
Web App Attack
πΊπΈ
craudiovizai
2026-08-15 12:30:30
(2 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-15 08:04:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 04:04:44.398563 2026] [security2:error] [pid 1917226:tid 1917284] [client 104.23.221.10:14016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robertjgarcia.securitymediaservices.com"] [uri "/.git/config"] [unique_id "aoAdnHM1TJvDVVAtkzT6EwAAAgk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TIScore
2026-08-14 15:28:20
(3 days ago)
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path ...
show more
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path. Last path: /wp-admin/install.php
show less
Web App Attack
πΊπΈ
craudiovizai
2026-08-14 06:30:48
(3 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-13 18:49:45
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 14:49:40.982379 2026] [security2:error] [pid 3114316:tid 3114316] [client 104.23.221.10:10668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wa211.org"] [uri "/.git/HEAD"] [unique_id "an4RxB0O8w4e-isAPh9JbAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TIScore
2026-08-13 15:28:11
(4 days ago)
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path ...
show more
Automated web attack / probing. Signals: Admin-panel scan; Foreign script extension; Unexpected path. Last path: /wp-admin/install.php
show less
Web App Attack