๐บ๐ธ
TPI-Abuse
2026-06-17 07:31:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 03:31:55.025741 2026] [security2:error] [pid 13935:tid 13935] [client 104.23.221.28:10027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aisoftwaretools.michaelthompson.biz"] [uri "/.git/config"] [unique_id "ajJNa9xWpkJ7CR2WHewtvQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-14 02:05:36
(3 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 23:27:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 19:27:38.758170 2026] [security2:error] [pid 17638:tid 17638] [client 104.23.221.28:12743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yulia.kronrod.com"] [uri "/.git/config"] [unique_id "aidP6qv_WdGrOb7GWfHFpgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 22:16:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:16:46.512532 2026] [security2:error] [pid 24931:tid 24931] [client 104.23.221.28:10839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jvwebinars.vanemby.com"] [uri "/.git/config"] [unique_id "aic_TlERwlAFkf-8c_vN3AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 16:50:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:50:19.227566 2026] [security2:error] [pid 9744:tid 9744] [client 104.23.221.28:11045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cultiplant.com.menagri.com"] [uri "/.git/config"] [unique_id "aibyy3iGGvPSbNF1EVxKFgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
omartin
2026-06-04 20:48:21
(1 week ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ท
omartin
2026-05-25 05:18:16
(3 weeks ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-05-24 20:19:12
(3 weeks ago)
scanning for potential vulnerable apps (wordpress etc.) and database accesses (GHR). Requested URI: ...
show more
scanning for potential vulnerable apps (wordpress etc.) and database accesses (GHR). Requested URI: /.git/config
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 14:32:10
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 10:32:02.974355 2026] [security2:error] [pid 7298:tid 7298] [client 104.23.221.28:12925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "a1laha.com"] [uri "/.git/config"] [unique_id "ahG6YnCyk0FHpdxKY0FZegAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 07:31:00
(4 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
omartin
2026-05-19 13:45:32
(4 weeks ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-05-18 15:53:58
(4 weeks ago)
[MonMay1817:53:54.7177482026][security2:error][pid1442400:tid1442511][client104.23.221.28:0]ModSecur ...
show more
[MonMay1817:53:54.7177482026][security2:error][pid1442400:tid1442511][client104.23.221.28:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.test.pytag.ch\"][uri\"/.env.development.local\"][unique_id\"ags2EhnW9kZf0gfT2sZOVgAAAQA\"]\,referer:https://www.google.com/search\?q=www.test.pytag.ch
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 12:53:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 08:53:01.468493 2026] [security2:error] [pid 24066:tid 24066] [client 104.23.221.28:13811] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamisongreen.com"] [uri "/.git/config"] [unique_id "agm6LfSYrSIkZNxWx69hRQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-05-14 15:57:29
(1 month ago)
๐จ Recon detected (nft drop)
SRC=104.23.221.28
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=104.23.221.28
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ณ๐ฑ
jjnxpct
2026-04-18 03:49:20
(1 month ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /wordpress/wp-admin/setup-config.php (Rule ID: 930130) - Restricted File Access Attempt
show less
Web App Attack
Hacking