๐ซ๐ท
UnixPrime
2026-09-07 19:29:20
(4 hours ago)
104.23.221.16 - - [07/Sep/2026:21:29:19 +0200] "GET /.env.local HTTP/1.1" 404 4130 "-" "Mozilla/5.0 ...
show more
104.23.221.16 - - [07/Sep/2026:21:29:19 +0200] "GET /.env.local HTTP/1.1" 404 4130 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.221.16 - - [07/Sep/2026:21:29:19 +0200] "GET /.env.old HTTP/1.1" 404 4133 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-07 13:02:21
(10 hours ago)
Accessed trap at '/wp-admin/install.php'
Web App Attack
๐ซ๐ท
omartin
2026-08-25 00:17:36
(1 week ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 05:51:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 01:51:26.317793 2026] [security2:error] [pid 1828:tid 1828] [client 104.23.221.16:10165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aviona.net"] [uri "/.git/HEAD"] [unique_id "aoVEXuA8Zw0F6yQML152bgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:38:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:38:39.681254 2026] [security2:error] [pid 30465:tid 30465] [client 104.23.221.16:10775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.digitaldatatechnologies.net"] [uri "/.git/config"] [unique_id "aoUzT3EmSr0skc20VNtUcQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:23:16
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:23:10.764349 2026] [security2:error] [pid 29596:tid 29596] [client 104.23.221.16:11130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grmvrr.powerlinemultimedia.net"] [uri "/.git/HEAD"] [unique_id "aoUvridS1IOBG3Ub6SGhfgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 03:11:12
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 23:11:08.415855 2026] [security2:error] [pid 30563:tid 30563] [client 104.23.221.16:13111] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ardath.net"] [uri "/.git/config"] [unique_id "aoUezNxa2I8CHnyuyMioUAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
omartin
2026-08-18 02:52:34
(2 weeks ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 21:25:17
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 17:25:09.337660 2026] [security2:error] [pid 28816:tid 28829] [client 104.23.221.16:11975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bakmail.net"] [uri "/.git/HEAD"] [unique_id "aoN8NUZofQ02_o_M7P-94QAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 16:14:06
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 12:13:59.007248 2026] [security2:error] [pid 13167:tid 13167] [client 104.23.221.16:14084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sarahpeebles.net"] [uri "/.git/config"] [unique_id "aoMzR3M39k72dWhSjsbcKwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-17 10:50:46
(3 weeks ago)
Automatic report - Vulnerability scan
/forum7/memberlist.php?mode=viewprofile&u=4&sid=44be26b9c6801d ...
show more
Automatic report - Vulnerability scan
/forum7/memberlist.php?mode=viewprofile&u=4&sid=44be26b9c6801dd43ed6ffc725567432
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:53:37
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:53:32.597137 2026] [security2:error] [pid 6751:tid 6751] [client 104.23.221.16:13243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thinksite.net"] [uri "/.git/config"] [unique_id "aoLMDOuqXMYcLIV5gp4ZMAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-17 01:50:29
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 01:47:26
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:47:21.283450 2026] [security2:error] [pid 20894:tid 20894] [client 104.23.221.16:10284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.krassa.net"] [uri "/.git/HEAD"] [unique_id "aoJoKSn2xh-ykCVF1_JjegAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 23:48:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:48:40.507774 2026] [security2:error] [pid 5135:tid 5135] [client 104.23.221.16:12915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.glolady.com"] [uri "/.git/HEAD"] [unique_id "aoJMWECNu-8ZDXLZXnKQywAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack