π¦πΉ
nomzamo
2026-06-14 15:53:17
(4 days ago)
Fail2Ban reported: nginx-noscript
Brute-Force
Bad Web Bot
π·πΊ
DZBOT
2026-06-14 10:20:45
(5 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 00:48:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 20:48:18.348016 2026] [security2:error] [pid 11413:tid 11413] [client 104.23.221.99:11387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.guardmagic.guardmagic.com"] [uri "/.env.old"] [unique_id "aioF0sMdJs_3ebaiLQjNjgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 02:46:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:46:21.572743 2026] [security2:error] [pid 20085:tid 20085] [client 104.23.221.99:13789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.indie100.com"] [uri "/.git/config"] [unique_id "aid-fSipQSEYJphM7Q5yAwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-05-29 22:06:49
(2 weeks ago)
Auto-ban: 12 malicious requests on 2026-05-28 (e.g., env/backup probes, brute-force, or error bursts ...
show more
Auto-ban: 12 malicious requests on 2026-05-28 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
π·πΊ
DZBOT
2026-05-20 15:16:20
(4 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-18 15:34:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 11:34:00.361463 2026] [security2:error] [pid 1528:tid 1546] [client 104.23.221.99:14323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.priyom.us"] [uri "/.env.dev"] [unique_id "agsxaK3ErD7LtOFdVMB9wgAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 19:35:46
(1 month ago)
(caddyscan) Scanner path probe from 104.23.221.99 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.23.221.99 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.221.99 - - [12/May/2026:19:33:16 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.99 - - [12/May/2026:19:33:27 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.99 - - [12/May/2026:19:34:24 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.99 - - [12/May/2026:19:35:21 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.221.99 - - [12/May/2026:19:35:37 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-04-23 18:51:17
(1 month ago)
Web App Attack
Brute-Force
Web App Attack
Anonymous
2026-04-18 14:56:19
(2 months ago)
Web App Attack
Brute-Force
Web App Attack
π¨π³
ThreatBook.io
2026-04-16 00:15:51
(2 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/104.23.221.99
20 ...
show more
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/104.23.221.99
2026-04-15 10:09:01 /wordpress/wp-admin/setup-config.php
show less
Web App Attack
π§π·
Halux
2026-03-30 12:53:47
(2 months ago)
104.23.221.99 Probing protected path or service
Web App Attack
Anonymous
2026-03-20 21:29:08
(2 months ago)
104.23.221.99 - - [20/Mar/2026:23:26:34 +0200] "GET /wp-admin/setup-config.php HTTP/1.0" 404 466 "-" ...
show more
104.23.221.99 - - [20/Mar/2026:23:26:34 +0200] "GET /wp-admin/setup-config.php HTTP/1.0" 404 466 "-" "https://pastoramigosimunyewu.com/wp-admin/setup-config.php"
104.23.221.99 - - [20/Mar/2026:23:26:34 +0200] "GET /wp-admin/setup-config.php HTTP/1.1" 404 286 "-" "https://pastoramigosimunyewu.com/wp-admin/setup-config.php"
104.23.221.99 - - [20/Mar/2026:23:26:38 +0200] "GET /wordpress/wp-admin/setup-config.php HTTP/1.0" 404 466 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
104.23.221.99 - - [20/Mar/2026:23:26:38 +0200] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 404 286 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
104.23.221.99 - - [20/Mar/2026:23:29:08 +0200] "GET /wp-admin/setup-config.php HTTP/1.0" 404 466 "-" "http://pastoramigosimunyewu.com/wp-admin/setup-config.php"
...
show less
Brute-Force
Web App Attack
π¬π§
no1knows.com
2026-02-09 16:56:12
(4 months ago)
2026/02/09 16:56:07 [error] 1616735#1616735: *34486 FastCGI sent in stderr: "Primary script unknown" ...
show more
2026/02/09 16:56:07 [error] 1616735#1616735: *34486 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 104.23.221.99, server: ldn.no1knows.com, request: "GET /wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com", referrer: "https://www.google.com"
2026/02/09 16:56:09 [error] 1616735#1616735: *34486 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 104.23.221.99, server: ldn.no1knows.com, request: "GET /wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com", referrer: "https://www.google.com"
2026/02/09 16:56:10 [error] 1616735#1616735: *34486 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 104.23.221.99, server: ldn.no1knows.com, request: "GET /wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com", referrer:
...
show less
Brute-Force
Bad Web Bot
π«π·
omartin
2026-02-09 02:53:27
(4 months ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack