๐บ๐ธ
mawan
2026-08-21 20:02:03
(1 day ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-08-20 12:39:59
(3 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:55:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:55:47.180896 2026] [security2:error] [pid 28375:tid 28375] [client 104.23.221.223:10972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.okeetokee.net"] [uri "/.git/HEAD"] [unique_id "aoU3U0Rul4_PQ_ndSayJVwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:28:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:28:19.449369 2026] [security2:error] [pid 3526:tid 3526] [client 104.23.221.223:9672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.studiopilates.net"] [uri "/.git/HEAD"] [unique_id "aoUw41TrV0O-cVKd1kCIoQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:10:44
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:10:38.303111 2026] [security2:error] [pid 21768:tid 21768] [client 104.23.221.223:10949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.method1.net"] [uri "/.git/HEAD"] [unique_id "aoUsvkoe2uAwlGOexUL7jAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 02:29:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:29:24.118381 2026] [security2:error] [pid 9316:tid 9316] [client 104.23.221.223:12165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staugustineflyfishing.net"] [uri "/.git/HEAD"] [unique_id "aoUVBFFal84JpXMiMMcdYwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 20:57:40
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 16:57:33.087994 2026] [security2:error] [pid 30622:tid 30622] [client 104.23.221.223:10144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "californialending.biz.californiaappraisers.net"] [uri "/.git/HEAD"] [unique_id "aoN1vfFn6gQHxhn2DoemEgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:13:43
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:13:36.081987 2026] [security2:error] [pid 3473:tid 3473] [client 104.23.221.223:9353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehandyfamily.net"] [uri "/.git/HEAD"] [unique_id "aoJuUF625pLRBh1fCJ2AWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 01:24:34
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:24:25.692581 2026] [security2:error] [pid 8282:tid 8282] [client 104.23.221.223:11558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arcadiapropertiesllc.starrmail.net"] [uri "/.git/HEAD"] [unique_id "aoJiybW-sjJvO2aIOtbQ4wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hagen Schoebel
2026-08-17 00:23:41
(6 days ago)
Blocked by CrowdSec - crowdsecurity/vpatch-git-config (SE)
Port Scan
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-08-16 23:46:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:46:04.309923 2026] [security2:error] [pid 13877:tid 13877] [client 104.23.221.223:10355] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stepiz62.com"] [uri "/.git/config"] [unique_id "aoJLvMFDNQlJzbVMipAt5AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 22:51:01
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:50:54.015923 2026] [security2:error] [pid 10623:tid 10623] [client 104.23.221.223:13933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.champions-in-arms.com"] [uri "/.git/config"] [unique_id "aoI-zjGLqA201wxG0k6kNgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:12:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:12:20.843844 2026] [security2:error] [pid 20323:tid 20323] [client 104.23.221.223:12427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.belmontsprings.ca"] [uri "/.git/HEAD"] [unique_id "aoFi1FnNvA4xSTMF-2mOzwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
myintarweb
2026-08-16 03:39:59
(1 week ago)
104.23.221.223 - - [16/Aug/2026:04:39:58 +0100] 443 "GET /.git/config HTTP/2.0" 404 1156 "-" "Mozill ...
show more
104.23.221.223 - - [16/Aug/2026:04:39:58 +0100] 443 "GET /.git/config HTTP/2.0" 404 1156 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
104.23.221.223 - - [16/Aug/2026:04:39:58 +0100] 443 "GET /.git/HEAD HTTP/2.0" 404 1156 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:36:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:36:50.046272 2026] [security2:error] [pid 1220:tid 1220] [client 104.23.221.223:11677] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.greatwesternfirearms.com"] [uri "/.git/config"] [unique_id "aoEwUjXn8ebzy9kalklJmQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack