๐ฐ๐ท
enp0s1
2026-06-28 14:27:27
(5 hours ago)
Auto-reported by Fail2Ban (UFW Block, Port Scan)
Port Scan
๐ง๐ฌ
Stoyko Stoykov
2026-06-26 18:35:21
(2 days ago)
104.23.221.100 - - [26/Jun/2026:21:35:21 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
104.23.221.100 - - [26/Jun/2026:21:35:21 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 162 "-" "-"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-25 22:40:46
(2 days ago)
Web App Attack
Brute-Force
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-25 16:13:28
(3 days ago)
104.23.221.100 - - [25/Jun/2026:19:13:28 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
104.23.221.100 - - [25/Jun/2026:19:13:28 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/2.0" 404 134 "-" "-"
...
show less
Hacking
Web App Attack
๐ท๐บ
DZBOT
2026-06-16 16:44:32
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 00:49:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 20:48:57.426600 2026] [security2:error] [pid 11942:tid 11942] [client 104.23.221.100:11576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guardmagic.eu"] [uri "/.env.local"] [unique_id "aioF-ROzfLKm-O0xtcHf5wAAABg"], referer: https://www.google.com/search?q=guardmagic.eu
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 22:51:31
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:51:22.248632 2026] [security2:error] [pid 24529:tid 24529] [client 104.23.221.100:10859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smog-test-coupons.smogsandiego.com"] [uri "/.git/config"] [unique_id "aidHau0kWrGeuSCazXGVbAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 21:55:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:55:44.733048 2026] [security2:error] [pid 11666:tid 11666] [client 104.23.221.100:9615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "curtin2011s2.tonylai.com"] [uri "/.git/config"] [unique_id "aic6YBLFLl2HeOdq9XrjwwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 17:26:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:26:21.157187 2026] [security2:error] [pid 14707:tid 14707] [client 104.23.221.100:11187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "major33.com.cruanyes.com"] [uri "/.git/config"] [unique_id "aib7Pa5v8qwKFlSr7yStMgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-03 03:55:35
(3 weeks ago)
104.23.221.100 - - [03/Jun/2026:06:55:35 +0300] "GET /.env.remote HTTP/2.0" 404 134 "-" "Mozilla/5.0 ...
show more
104.23.221.100 - - [03/Jun/2026:06:55:35 +0300] "GET /.env.remote HTTP/2.0" 404 134 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
oncord
2026-05-31 11:09:52
(4 weeks ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-05-24 12:33:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 08:32:55.320673 2026] [security2:error] [pid 11158:tid 11158] [client 104.23.221.100:13649] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinnaird.enterprises.pages4you.com"] [uri "/.git/config"] [unique_id "ahLv90f1egNqXD4PZzIVgwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 18:34:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 14:34:06.012156 2026] [security2:error] [pid 30767:tid 30767] [client 104.23.221.100:12311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calificacionyvalidacionsicav.com"] [uri "/.git/config"] [unique_id "ahHzHgJWijga-Mqe3AaPFQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 16:54:18
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 12:54:10.556932 2026] [security2:error] [pid 19347:tid 19347] [client 104.23.221.100:11625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nationaljar.com"] [uri "/.git/config"] [unique_id "ahHbskAsf0A7Laiki70Y3gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-05-20 16:21:27
(1 month ago)
URL scan
Brute-Force
Web App Attack