๐บ๐ธ
TPI-Abuse
2026-09-25 20:38:53
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 16:38:49.553846 2026] [security2:error] [pid 7820:tid 7820] [client 104.23.223.138:13482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ilanknapp.com"] [uri "/.git/config"] [unique_id "arbb2UNJ6cc59adfacNKeAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 07:06:23
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
4server
2026-09-04 19:45:26
(3 weeks ago)
[FriSep0421:45:20.9543902026][security2:error][pid594666:tid594783][client104.23.223.138:0]ModSecuri ...
show more
[FriSep0421:45:20.9543902026][security2:error][pid594666:tid594783][client104.23.223.138:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"modularss.com\"][uri\"/.netrc\"][unique_id\"apsf0LXxguEJm1XE1Ta3zQAAAQc\"]\,referer:https://www.google.com/search\?q=modularss.com
show less
Port Scan
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-09-01 02:23:07
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
wolfemium
2026-08-28 21:16:23
(4 weeks ago)
104.23.223.138 - - [29/Aug/2026:00:16:22 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
104.23.223.138 - - [29/Aug/2026:00:16:22 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 502 150 "-" "-"
104.23.223.138 - - [29/Aug/2026:00:16:22 +0300] "GET //adminfuns.php HTTP/1.1" 502 150 "-" "-"
104.23.223.138 - - [29/Aug/2026:00:16:22 +0300] "GET /about.php? HTTP/1.1" 502 150 "-" "-"
104.23.223.138 - - [29/Aug/2026:00:16:23 +0300] "GET /admin.php? HTTP/1.1" 502 150 "-" "-"
104.23.223.138 - - [29/Aug/2026:00:16:23 +0300] "GET /coffexium.php HTTP/1.1" 502 150 "-" "-"
104.23.223.138 - - [29/Aug/2026:00:16:23 +0300] "GET /wp-ws68.php?p= HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 15:35:26
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:09:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:09:18.749039 2026] [security2:error] [pid 11234:tid 11234] [client 104.23.223.138:9470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.srossi.net"] [uri "/.git/config"] [unique_id "aoUsbuykTF-q8YZNgHMr9gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 03:52:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 23:51:56.657424 2026] [security2:error] [pid 3015:tid 3015] [client 104.23.223.138:12936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.flugstad.net"] [uri "/.git/config"] [unique_id "aoUoXPhPRSQVgO9aWgS3rwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 02:48:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:48:07.117253 2026] [security2:error] [pid 19385:tid 19395] [client 104.23.223.138:12999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.seasonsgreeters.net"] [uri "/.git/config"] [unique_id "aoUZZ88aOZrAqYQnFzOnUQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 16:13:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 12:13:52.200186 2026] [security2:error] [pid 14245:tid 14245] [client 104.23.223.138:9291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rainwaterconstruction.net"] [uri "/.git/config"] [unique_id "aoMzQI9Z2O7PeA_tUHrneQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:46:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:46:50.969839 2026] [security2:error] [pid 22161:tid 22161] [client 104.23.223.138:10250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.intermixx.net"] [uri "/.git/config"] [unique_id "aoLKeitwUJjVIZ_GJ--m2wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:01:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:01:28.835538 2026] [security2:error] [pid 14840:tid 14840] [client 104.23.223.138:13380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.infraredovens.net"] [uri "/.git/config"] [unique_id "aoJ5iCUnWZOk_gwtbt_e4AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 01:25:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:25:34.451295 2026] [security2:error] [pid 11137:tid 11176] [client 104.23.223.138:13479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bakmail.net"] [uri "/.git/HEAD"] [unique_id "aoJjDl7W0poX2GoMC3xAYgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 23:34:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:34:44.317542 2026] [security2:error] [pid 21600:tid 21600] [client 104.23.223.138:10223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.georgegourmet.com"] [uri "/.git/config"] [unique_id "aoJJFEA3LAzUAO1VFUOnVQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-08-16 23:07:50
(1 month ago)
104.23.223.138 - - [17/Aug/2026:01:07:49 +0200] "GET /.git/config HTTP/2.0" 403 69 "-" "Mozilla/5.0 ...
show more
104.23.223.138 - - [17/Aug/2026:01:07:49 +0200] "GET /.git/config HTTP/2.0" 403 69 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack