๐บ๐ธ
TPI-Abuse
2026-09-30 12:50:22
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:50:18.103613 2026] [security2:error] [pid 5440:tid 5440] [client 104.23.221.82:10792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portlunchgroup.com"] [uri "/.git/config"] [unique_id "ar0FimxesrtsSWAX6XECwQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:04:39
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:04:34.001973 2026] [security2:error] [pid 14833:tid 14833] [client 104.23.221.82:9826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "developerdove.com"] [uri "/.git/config"] [unique_id "aryKUrDQ1TnqZ2z_MxMkkAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:53:44
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:53:38.901793 2026] [security2:error] [pid 19432:tid 19432] [client 104.23.221.82:9415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "camerongunsmith.com"] [uri "/.git/config"] [unique_id "arxdkjCPuyLydw462diA8gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-29 23:49:54
(19 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 2 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:58:28
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:58:23.517528 2026] [security2:error] [pid 23910:tid 23910] [client 104.23.221.82:11326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.shukrisharawico.com"] [uri "/.git/config"] [unique_id "arw0f5Se_rwCp40uA6fG1wAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-27 10:37:58
(3 days ago)
[SunSep2712:37:57.3245652026][security2:error][pid3521192:tid3521254][client104.23.221.82:0]ModSecur ...
show more
[SunSep2712:37:57.3245652026][security2:error][pid3521192:tid3521254][client104.23.221.82:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:user-agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"sanierung-pilzen-schimmel.ch\"][uri\"/.git/config\"][unique_id\"arjyBSmBHRnbdALM4nPcLQAAAIE\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-09-27 09:51:10
(3 days ago)
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:04 +0200] "GET /wp-admin/css/spjRmJO.php HTTP/1.1" 4 ...
show more
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:04 +0200] "GET /wp-admin/css/spjRmJO.php HTTP/1.1" 404 236 "-" "-"
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:04 +0200] "GET /wp-admin/js/widgets/alfa-rex.php HTTP/1.1" 404 236 "-" "-"
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:06 +0200] "GET /wp-admin/js/widgets/wp-login.php HTTP/1.1" 404 236 "-" "-"
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:06 +0200] "GET /wp-admin/includes/class-wp-community-events-security.php HTTP/1.1" 404 236 "-" "-"
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:07 +0200] "GET /wp-admin/css/PXmpeIJJ.php HTTP/1.1" 404 236 "-" "-"
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:08 +0200] "GET /wp-admin/css/1b2f09eda1ea40.php HTTP/1.1" 404 236 "-" "-"
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:08 +0200] "GET /wp-admin/includes/fff.php HTTP/1.1" 404 236 "-" "-"
[redacted] 104.23.221.82 - - [27/Sep/2026:11:51:08 +0200] "GET /wp-admin/includes/rfatW.php HTTP/1.
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 17:10:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 13:10:46.066000 2026] [security2:error] [pid 31826:tid 31826] [client 104.23.221.82:13660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "happyskinhappylife.com"] [uri "/.git/config"] [unique_id "ararFv5UAzk7QLWIxb3voAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 14:20:45
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 10:20:42.833776 2026] [security2:error] [pid 19749:tid 19749] [client 104.23.221.82:14264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graficasbis.com"] [uri "/.git/config"] [unique_id "araDOtenea5EolZsMvDB8QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 11:37:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 07:37:00.554623 2026] [security2:error] [pid 24645:tid 24645] [client 104.23.221.82:11081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bethanpearce.com"] [uri "/.git/config"] [unique_id "arZc3PYiGCAM0tG9IOWP6wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-09-13 17:42:23
(2 weeks ago)
bad bot
Bad Web Bot
๐ฎ๐ช
Coolnagour
2026-09-12 08:02:02
(2 weeks ago)
funnypot web honeypot, port 443: GET /.env.production
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-09-03 01:53:21
(3 weeks ago)
bad bot
Bad Web Bot
๐ธ๐ฌ
anotherwatcher
2026-08-29 01:52:52
(1 month ago)
bad bot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-19 05:18:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 01:18:25.270558 2026] [security2:error] [pid 6511:tid 6511] [client 104.23.221.82:13201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whiterhinogroup.net"] [uri "/.git/HEAD"] [unique_id "aoU8oZQtO-f-EwYw0nTMLgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack