๐ณ๐ด
jad-abuse
2026-09-13 21:41:23
(13 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 7 hits.
show less
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-09-09 15:49:35
(4 days ago)
Web App Attack
๐ฉ๐ช
kkw
2026-09-08 01:11:30
(6 days ago)
[REDACTED] 104.23.223.28 - - [08/Sep/2026:03:11:30 +0200] "GET /.git/config HTTP/2.0" 404 3647 "-" " ...
show more
[REDACTED] 104.23.223.28 - - [08/Sep/2026:03:11:30 +0200] "GET /.git/config HTTP/2.0" 404 3647 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/127.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-01 06:30:55
(1 week ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ฌ๐ง
cg-design.co.uk
2026-09-01 05:28:23
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 104.23.223.28 (SE/Sweden/-)
SQL Injection
Anonymous
2026-08-27 23:07:29
(2 weeks ago)
Trying to access config files
Web App Attack
Anonymous
2026-08-26 16:06:07
(2 weeks ago)
Trying to access config files
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-26 13:02:38
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: LOCALE-PROBE: MissingSlash (/PT21518wp-admin/install.php)
show less
Hacking
Exploited Host
Web App Attack
๐ท๐บ
DZBOT
2026-08-24 05:40:36
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 06:48:59
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 02:48:54.224182 2026] [security2:error] [pid 10014:tid 10014] [client 104.23.223.28:10268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.coast22.net"] [uri "/.git/HEAD"] [unique_id "aoVR1tMjcrCx3SswahPVDwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 06:25:55
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 02:25:49.229278 2026] [security2:error] [pid 26642:tid 26687] [client 104.23.223.28:14036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bakmail.net"] [uri "/.git/config"] [unique_id "aoVMbTl1in_qcgtWEFpL1QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:29:41
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:29:34.826441 2026] [security2:error] [pid 16751:tid 16751] [client 104.23.223.28:10274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aikomp.net"] [uri "/.git/config"] [unique_id "aoUxLq3ExwrAyaq39-Zv4wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 03:37:54
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 23:37:51.096884 2026] [security2:error] [pid 1017:tid 1017] [client 104.23.223.28:11315] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stringview.antech.net"] [uri "/.git/config"] [unique_id "aoUlDwKPFOt5BZZziDmN_QAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 02:21:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:21:53.725427 2026] [security2:error] [pid 6826:tid 6826] [client 104.23.223.28:13584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.scotts.net"] [uri "/.git/HEAD"] [unique_id "aoUTQXP-KswFRudG-AssAgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 21:25:22
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 17:25:09.984505 2026] [security2:error] [pid 17491:tid 17491] [client 104.23.223.28:13600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bartholow.net"] [uri "/.git/config"] [unique_id "aoN8Nf4EQB3ZAGfnW4q-DgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack