๐ฒ๐ฝ
octageeks.com
2026-06-11 04:13:12
(16 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฉ๐ช
strxmpp
2026-06-11 03:26:08
(17 hours ago)
104.23.223.108 - - [11/Jun/2026:05:26:07 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 681 ...
show more
104.23.223.108 - - [11/Jun/2026:05:26:07 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 681 "-" "http://jabberzueri.ch/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-08 23:14:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 19:14:33.829040 2026] [security2:error] [pid 26581:tid 26581] [client 104.23.223.108:13415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.perissosdigitalmarketing.com.kevinfranz.com"] [uri "/.env"] [unique_id "aidM2cp9R992qS8XqrxRnwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 21:52:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:52:13.367919 2026] [security2:error] [pid 18657:tid 18657] [client 104.23.223.108:11185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jbmitchelllaw.com"] [uri "/.git/config"] [unique_id "aic5jcjqvniW9Se7NRZEUQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-05-21 04:09:15
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 08:48:58
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 17:14:14
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 13:14:08.976858 2026] [security2:error] [pid 29987:tid 30011] [client 104.23.223.108:13427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "motoadvrally.com"] [uri "/.git/config"] [unique_id "agn3YNajKzuFPLaixYm54gAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-05-17 04:07:58
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 11:49:39
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 07:49:30.626918 2026] [security2:error] [pid 22919:tid 22924] [client 104.23.223.108:13221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aafm.org"] [uri "/.env.production"] [unique_id "agRlSikrBad4A3IuJdDgYQAAAQI"], referer: https://www.google.com/search?q=webdisk.aafm.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-05-13 03:50:19
(4 weeks ago)
HTTP attack observed: GET /wp-admin/install.php?step=1 HTTP/2.0 | status=404 | response_size=196
Brute-Force
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-05-13 03:50:19
(4 weeks ago)
HTTP attacks observed: GET /wp-admin/install.php?step=1 HTTP/2.0 | status=404
Brute-Force
Anonymous
2026-05-12 19:34:20
(4 weeks ago)
(caddyscan) Scanner path probe from 104.23.223.108 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.23.223.108 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.223.108 - - [12/May/2026:18:42:01 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.223.108 - - [12/May/2026:19:33:10 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.223.108 - - [12/May/2026:19:33:16 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.223.108 - - [12/May/2026:19:33:36 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.223.108 - - [12/May/2026:19:34:15 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-04-17 01:23:06
(1 month ago)
104.23.223.108 - - [17/Apr/2026:04:22:38 +0300] "GET /wp-content/uploads/about.php HTTP/1.1" 404 628 ...
show more
104.23.223.108 - - [17/Apr/2026:04:22:38 +0300] "GET /wp-content/uploads/about.php HTTP/1.1" 404 628 "-" "-"
104.23.223.108 - - [17/Apr/2026:04:23:04 +0300] "GET /wp-includes/ HTTP/1.1" 404 628 "-" "-"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-01 10:33:38
(2 months ago)
104.23.223.108 - - [01/Apr/2026:13:31:41 +0300] "GET /wp-includes/widgets/ HTTP/1.1" 404 714 "-" "Mo ...
show more
104.23.223.108 - - [01/Apr/2026:13:31:41 +0300] "GET /wp-includes/widgets/ HTTP/1.1" 404 714 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
104.23.223.108 - - [01/Apr/2026:13:33:36 +0300] "GET /wp-includes/block-patterns/ HTTP/1.1" 404 714 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
omartin
2026-01-22 02:41:56
(4 months ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack