๐ธ๐ฌ
securejdprop
2026-06-03 02:55:29
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing. crowdsecurity/http-probing
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 06:28:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 02:28:02.022249 2026] [security2:error] [pid 15332:tid 15353] [client 104.23.221.11:10157] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dermatologistsanantonio.aafm.us"] [uri "/.env.dev"] [unique_id "ahPr8j4M4F0WmMtLsH5IzwAAAdM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-05-24 10:06:01
(1 week ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-23 16:06:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 12:06:49.070751 2026] [security2:error] [pid 26134:tid 26134] [client 104.23.221.11:13030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "k2medianetworks.com"] [uri "/.git/config"] [unique_id "ahHQmbxdZmQpJbEXa7vFVwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-22 21:59:30
(1 week ago)
Auto-ban: >3000 req/min op 2026-05-22
Web App Attack
SSH
Hacking
๐ท๐บ
DZBOT
2026-05-20 08:42:38
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 13:34:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 09:34:31.654417 2026] [security2:error] [pid 32276:tid 32276] [client 104.23.221.11:10768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internet-brochures.com"] [uri "/.git/config"] [unique_id "agnD5-73jHc2dkDv-t7edQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-15 03:45:33
(3 weeks ago)
104.23.221.11 - - [15/May/2026:06:45:33 +0300] "GET /wp-content/plugins/index.php HTTP/1.1" 404 3296 ...
show more
104.23.221.11 - - [15/May/2026:06:45:33 +0300] "GET /wp-content/plugins/index.php HTTP/1.1" 404 3296 "-" "Go-http-client/2.0"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-13 18:31:06
(3 weeks ago)
104.23.221.11 - - [13/May/2026:21:31:06 +0300] "GET /wp-content/file.php HTTP/1.1" 404 736 "-" "Mozi ...
show more
104.23.221.11 - - [13/May/2026:21:31:06 +0300] "GET /wp-content/file.php HTTP/1.1" 404 736 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-11 08:00:31
(3 weeks ago)
104.23.221.11 - - [11/May/2026:11:00:29 +0300] "GET /wp-content/index.php HTTP/1.1" 404 628 "-" "-"
...
show more
104.23.221.11 - - [11/May/2026:11:00:29 +0300] "GET /wp-content/index.php HTTP/1.1" 404 628 "-" "-"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-09 09:21:23
(3 weeks ago)
104.23.221.11 - - [09/May/2026:12:21:23 +0300] "GET /wp-content/packed.php HTTP/1.1" 404 628 "-" "-" ...
show more
104.23.221.11 - - [09/May/2026:12:21:23 +0300] "GET /wp-content/packed.php HTTP/1.1" 404 628 "-" "-"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-08 22:00:06
(3 weeks ago)
104.23.221.11 - - [09/May/2026:01:00:05 +0300] "GET /wp-includes/ HTTP/1.1" 404 736 "-" "Mozilla/5.0 ...
show more
104.23.221.11 - - [09/May/2026:01:00:05 +0300] "GET /wp-includes/ HTTP/1.1" 404 736 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-08 10:31:18
(4 weeks ago)
104.23.221.11 - - [08/May/2026:13:31:17 +0300] "GET /wp-content/themes/twentytwenty/404.php HTTP/1.1 ...
show more
104.23.221.11 - - [08/May/2026:13:31:17 +0300] "GET /wp-content/themes/twentytwenty/404.php HTTP/1.1" 404 3296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ธ๐ฌ
securejdprop
2026-05-07 21:12:08
(4 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing. crowdsecurity/http-probing
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-07 13:36:32
(4 weeks ago)
104.23.221.11 - - [07/May/2026:16:36:32 +0300] "GET /wp-content/themes/about.php HTTP/1.1" 404 736 " ...
show more
104.23.221.11 - - [07/May/2026:16:36:32 +0300] "GET /wp-content/themes/about.php HTTP/1.1" 404 736 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.221.11 - - [07/May/2026:16:36:32 +0300] "GET /wp-content/upgrade/index.php HTTP/1.1" 404 736 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack