๐บ๐ธ
TPI-Abuse
2026-06-13 12:50:15
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:50:05.661683 2026] [security2:error] [pid 9524:tid 9524] [client 104.23.221.81:9496] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "web239.dnchosting.com"] [uri "/.git/config"] [unique_id "ai1R_Z-5Ak-NOeIqnlBeXAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sc user
2026-06-12 07:08:54
(3 days ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฌ๐ง
sc user
2026-06-10 09:43:59
(5 days ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฉ๐ช
langenkamp-media
2026-06-10 05:00:24
(5 days ago)
Fail2Ban: Banned from jail nginx-nohome on 3dausdu.de
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 02:21:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:21:02.122567 2026] [security2:error] [pid 2097:tid 2097] [client 104.23.221.81:10336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fpstudios.puoci.com"] [uri "/.git/config"] [unique_id "aid4jtrwiHXCiPL42GQFywAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-06 16:01:01
(1 week ago)
Web App Attack
๐ท๐บ
DZBOT
2026-05-25 04:43:36
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ญ
backslash
2026-05-24 05:21:03
(3 weeks ago)
Bad Web Bot
๐ฆ๐บ
oncord
2026-05-24 03:21:30
(3 weeks ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-05-17 14:30:46
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 10:30:38.542266 2026] [security2:error] [pid 388:tid 388] [client 104.23.221.81:10858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marisa-mcphee.com"] [uri "/.git/config"] [unique_id "agnRDgZR8_6Zwg4x7ICS3AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 00:31:01
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 20:30:56.232321 2026] [security2:error] [pid 12219:tid 12219] [client 104.23.221.81:10365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jjhfamily.com"] [uri "/.env.dev"] [unique_id "age6wOPqz70YOTiTwYoUUQAAAAo"], referer: https://www.google.com/search?q=jjhfamily.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-05-14 06:14:35
(1 month ago)
Form spam
Web Spam
Anonymous
2026-05-13 18:22:03
(1 month ago)
(caddyscan) Scanner path probe from 104.23.221.81 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.23.221.81 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.221.81 - - [13/May/2026:17:54:32 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 104.23.221.81 - - [13/May/2026:17:54:32 +0000] "GET /.env.development HTTP/1.1"
[REDACTED] 200 2627 104.23.221.81 - - [13/May/2026:17:54:47 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 104.23.221.81 - - [13/May/2026:17:54:47 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 104.23.221.81 - - [13/May/2026:18:22:00 +0000] "GET /.env.dev HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-13 11:39:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 07:38:55.496365 2026] [security2:error] [pid 31067:tid 31067] [client 104.23.221.81:11800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mickbarton.com"] [uri "/.env.local"] [unique_id "agRiz5UEXkHWDWfCWX-qwgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 19:35:15
(1 month ago)
(caddyscan) Scanner path probe from 104.23.221.81 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.23.221.81 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.221.81 - - [12/May/2026:19:33:07 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.81 - - [12/May/2026:19:33:13 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.81 - - [12/May/2026:19:33:32 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.81 - - [12/May/2026:19:33:48 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.81 - - [12/May/2026:19:35:09 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan