๐บ๐ธ
TPI-Abuse
2026-06-17 13:13:24
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 09:13:18.404479 2026] [security2:error] [pid 2752:tid 2752] [client 104.23.221.179:9438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naomipyle.com.joshuashands.org"] [uri "/.git/config"] [unique_id "ajKdbnsgtW0-EnQZk1SI6AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-14 03:36:10
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 20:48:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 16:48:13.414270 2026] [security2:error] [pid 10138:tid 10174] [client 104.23.221.179:11828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mtiminis.com"] [uri "/.env"] [unique_id "ai3CDXf6QvVGxbWBCUGEfgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 03:04:57
(1 week ago)
104.23.221.179 - - [13/Jun/2026:03:04:56 +0000] "GET /.env HTTP/1.1" 302 5010 "https://www.google.co ...
show more
104.23.221.179 - - [13/Jun/2026:03:04:56 +0000] "GET /.env HTTP/1.1" 302 5010 "https://www.google.com/search?q=www.gassycat.co.uk" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-10 04:24:22
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 02:33:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:33:39.646572 2026] [security2:error] [pid 25371:tid 25386] [client 104.23.221.179:9961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killyourattitude.missmadlove.com"] [uri "/.git/config"] [unique_id "aid7g9yyfpz8z56Xs5FdTQAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 17:15:13
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 13:15:05.860449 2026] [security2:error] [pid 18956:tid 18975] [client 104.23.221.179:13376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pwrcoupling.com"] [uri "/.git/config"] [unique_id "ahHgmW_ryKYXW8Pa47SGlwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 11:36:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 07:36:10.359620 2026] [security2:error] [pid 2604:tid 2604] [client 104.23.221.179:9870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paintscapeabroad.com"] [uri "/.git/config"] [unique_id "ahGRKhCnUE7cH-ZkQiTmfgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 18:38:44
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-17 22:00:01
(1 month ago)
Auto-ban: >3000 req/min op 2026-05-17
Web App Attack
SSH
Hacking
Anonymous
2026-05-12 19:35:20
(1 month ago)
(caddyscan) Scanner path probe from 104.23.221.179 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.23.221.179 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.221.179 - - [12/May/2026:19:33:16 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.179 - - [12/May/2026:19:33:33 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.179 - - [12/May/2026:19:33:50 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.179 - - [12/May/2026:19:34:27 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.179 - - [12/May/2026:19:35:12 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-05-12 17:15:40
(1 month ago)
HTTP attack observed: GET /wp-admin/install.php?step=1 HTTP/1.1 | status=301 | response_size=253
Port Scan
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-05-12 17:15:40
(1 month ago)
HTTP attacks observed: GET /wp-admin/install.php?step=1 HTTP/1.1 | status=301
Port Scan
๐จ๐ฆ
dispensight
2026-05-12 13:00:00
(1 month ago)
WordPress UA-spoofed probe (400). Cloudflare proxy, Sweden. Referrer: dispensight.forum (Dispensight ...
show more
WordPress UA-spoofed probe (400). Cloudflare proxy, Sweden. Referrer: dispensight.forum (Dispensight Clown Vacuum).
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
www.mammazone.it
2026-04-30 04:36:41
(1 month ago)
[Thu Apr 30 06:36:40.581643 2026] [autoindex:error] [pid 3310927] [client 104.23.221.179:13401] AH01 ...
show more
[Thu Apr 30 06:36:40.581643 2026] [autoindex:error] [pid 3310927] [client 104.23.221.179:13401] AH01276: Cannot serve directory /var/www/fabiodirauso.it/.well-known/: No matching DirectoryIndex (index.html,index.cgi,index.pl,index.php,index.xhtml,index.htm) found, and server-generated directory index forbidden by Options directive
...
show less
Hacking
Web App Attack