πΊπΈ
TPI-Abuse
2026-09-30 14:04:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:04:23.141840 2026] [security2:error] [pid 11027:tid 11027] [client 104.23.221.91:10372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "musicpolitan.com"] [uri "/.git/config"] [unique_id "ar0W5852cKpO0j6iGz6iwQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 03:50:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:50:03.067728 2026] [security2:error] [pid 17664:tid 17664] [client 104.23.221.91:12068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcwenger.com"] [uri "/.git/config"] [unique_id "aryG651MPQ5uS9OFQXhB-wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-29 01:39:13
(1 week ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π΅πΈ
ManFromWorld
2026-09-27 11:51:00
(2 weeks ago)
DDoS Attack
Brute-Force
Bad Web Bot
Web App Attack
Web Spam
Fraud VoIP
Hacking
Blog Spam
πΊπΈ
TPI-Abuse
2026-09-27 07:05:14
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 03:05:06.924780 2026] [security2:error] [pid 28246:tid 28246] [client 104.23.221.91:10367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sporttaekwondo.net"] [uri "/.git/config"] [unique_id "arjAIshnaONYQkic7rrMBgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-27 01:47:25
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-27 00:28:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:28:50.765736 2026] [security2:error] [pid 901:tid 901] [client 104.23.221.91:12648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glaswood.com"] [uri "/.git/config"] [unique_id "arhjQtJaDAoOQb2eARiysQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 09:14:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 05:14:23.430327 2026] [security2:error] [pid 23142:tid 23142] [client 104.23.221.91:9679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomslawmd.com"] [uri "/.git/config"] [unique_id "areM70PU7oyfzxVmy5zRmAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-09-12 07:08:44
(4 weeks ago)
Web App Attack
π³π±
homeshowdomain.nl
2026-09-08 22:04:11
(1 month ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
π¨π
backslash
2026-09-08 01:51:00
(1 month ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
π·πΊ
DZBOT
2026-08-28 13:46:33
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 05:24:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 01:24:02.146896 2026] [security2:error] [pid 3603:tid 3603] [client 104.23.221.91:11976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.royalchess.net"] [uri "/.git/config"] [unique_id "aoU98kvClKWB2xyARDpsdAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 05:07:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 01:07:23.901373 2026] [security2:error] [pid 16095:tid 16095] [client 104.23.221.91:10667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sabbathseminars.net"] [uri "/.git/config"] [unique_id "aoU6C1SCDcIeAvkx51UpfAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Michel Wijnberg
2026-08-19 04:50:15
(1 month ago)
104.23.221.91 - - [19/Aug/2026:04:50:15 +0000] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Mozilla/5.0 (W ...
show more
104.23.221.91 - - [19/Aug/2026:04:50:15 +0000] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack