πΊπΈ
TPI-Abuse
2026-10-10 07:18:10
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 03:18:06.163388 2026] [security2:error] [pid 2745:tid 2745] [client 104.23.223.172:9927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afjm.info"] [uri "/.git/config"] [unique_id "asnmri8SDyTu1g39YXlE6wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 22:53:07
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 18:53:03.374841 2026] [security2:error] [pid 26061:tid 26061] [client 104.23.223.172:9244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vicmackenzie.com"] [uri "/.git/config"] [unique_id "aslwT06CCThYtqYz3BfNqAAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 18:52:37
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:52:32.423941 2026] [security2:error] [pid 17318:tid 17318] [client 104.23.223.172:14128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rblep.com"] [uri "/.git/config"] [unique_id "ask38K5-Flcih7d7WUt95QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 14:10:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 10:10:09.993905 2026] [security2:error] [pid 29515:tid 29515] [client 104.23.223.172:9978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "labelrecord.com"] [uri "/.git/config"] [unique_id "asj1wQBbCmtebllKMSdAFQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 11:33:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 07:33:41.903302 2026] [security2:error] [pid 30711:tid 30711] [client 104.23.223.172:10884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "major33.com"] [uri "/.git/config"] [unique_id "asjRFVrReKIKmQr8-O-PRQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 07:19:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 03:19:14.616173 2026] [security2:error] [pid 4265:tid 4273] [client 104.23.223.172:13572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deyyoungart.com"] [uri "/.git/config"] [unique_id "asiVch74pcF2NNbbVZ4YRgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 05:02:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:02:13.790770 2026] [security2:error] [pid 5887:tid 5887] [client 104.23.223.172:13880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artbycorinnedodge.com"] [uri "/.git/config"] [unique_id "ash1VRSjzA4awzAV1ounaQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
securejdprop
2026-10-09 00:42:03
(1 day ago)
This IP was detected by CrowdSec triggering custom/vpatch-phpinstall.
Hacking
πΊπΈ
craudiovizai
2026-10-09 00:30:47
(1 day ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php?step=1. Blocked at the edge.
show less
Bad Web Bot
πΊπΈ
craudiovizai
2026-10-08 00:30:36
(2 days ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php, /wp-admin/install.php?step=1. Blocked at the edge.
show less
Bad Web Bot
πΊπΈ
craudiovizai
2026-10-07 12:30:35
(3 days ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php?step=1. Blocked at the edge.
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-05 21:59:44
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:59:39.680847 2026] [security2:error] [pid 31490:tid 31490] [client 104.23.223.172:13756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mlharris57.ohnosound.com"] [uri "/.git/config"] [unique_id "asQdy_SVSo3uIBISaE3gCAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2026-10-04 22:24:45
(5 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: \.php($|\?) (Match: .php?)
show less
Hacking
Exploited Host
Web App Attack
πΊπΈ
craudiovizai
2026-10-04 06:30:32
(6 days ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php?step=1, /wp-admin/install.php. Blocked at the edge.
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-04 03:38:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 23:38:02.028589 2026] [security2:error] [pid 6420:tid 6420] [client 104.23.223.172:13866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newlindendeli.royal-barbershop.com"] [uri "/.git/config"] [unique_id "asHKGu5bdss0_MGx7NAMjgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack