๐ฉ๐ช
altenglaner
2026-10-04 07:23:42
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 02:56:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 22:56:43.654947 2026] [security2:error] [pid 26365:tid 26365] [client 104.23.221.77:14199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vycestudiojuridico.cl"] [uri "/.git/config"] [unique_id "asHAa80H_rE-MQVIHlTLkgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-10-03 18:18:00
(2 days ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐ฉ๐ช
sternwart
2026-10-02 20:29:20
(3 days ago)
Automatisch erkannt: Zugriff auf /.git/config (xn--waschbr-alarm-gfb.ch)
Web App Attack
Bad Web Bot
๐ง๐ช
madeit
2026-10-01 06:30:25
(5 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:14:37
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:14:34.505795 2026] [security2:error] [pid 13020:tid 13020] [client 104.23.221.77:9892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jolankagroup.com"] [uri "/.git/config"] [unique_id "arzhCjkAJriODzkCI8T_GAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:17:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:17:04.838077 2026] [security2:error] [pid 18610:tid 18610] [client 104.23.221.77:12921] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigskyprints.com"] [uri "/.git/config"] [unique_id "arx_MO1lTlbCiSUl79zZcAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 07:48:07
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 03:48:01.973376 2026] [security2:error] [pid 4247:tid 4247] [client 104.23.221.77:13998] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "thebealcompany.net"] [uri "/.git/config"] [unique_id "arjKMdtk9KBfKCfStQdXYQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-27 05:12:12
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 02:27:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 22:27:10.202878 2026] [security2:error] [pid 9958:tid 9958] [client 104.23.221.77:12425] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kylight.net"] [uri "/.git/config"] [unique_id "arh-_rZLA2DUo6ECY2S7BwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-27 01:45:18
(1 week ago)
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.23.221.77 - - [27/Sep/2026:03:45:11 +0200] "GET /.git/config HTTP/2.0" 403 1963 "-" "Wget/1.21.3 (linux-gnu)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 00:34:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:34:23.547446 2026] [security2:error] [pid 23361:tid 23361] [client 104.23.221.77:11852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldenfrytech.net"] [uri "/.git/config"] [unique_id "arhkj0u1TqXPowLRd3zPTwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-24 06:10:27
(1 week ago)
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-20 22:10:06
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: \.php($|\?) (Match: .php?)
show less
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-19 16:50:13
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: \.php($|\?) (Match: .php?)
show less
Hacking
Exploited Host
Web App Attack