๐บ๐ธ
TPI-Abuse
2026-09-25 11:50:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 07:50:47.608287 2026] [security2:error] [pid 5340:tid 5340] [client 104.23.223.29:11782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "commercialphotostudiorental.com"] [uri "/.git/config"] [unique_id "arZgFwwfsH-rQEJBPFbRagAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-24 10:33:05
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: LOCALE-PROBE: MissingSlash (/PT21518wp-admin/install.php)
show less
Hacking
Exploited Host
Web App Attack
๐ง๐ช
madeit
2026-09-24 00:16:48
(1 day ago)
Web App Attack
๐ง๐ช
madeit
2026-09-12 07:02:47
(1 week ago)
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-09-11 15:02:19
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 104.23.223.29 (SE/Sweden/-)
SQL Injection
๐ณ๐ด
jad-abuse
2026-09-10 14:05:45
(2 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 5 hits.
show less
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-09-08 06:48:29
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
tecnicorioja
2026-09-03 22:00:19
(3 weeks ago)
wp-login attack [03/Sep/2026:05:14:04
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-02 04:08:53
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-25 12:22:39
(1 month ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: LOCALE-PROBE: MissingSlash (/PT21518wp-admin/install.php)
show less
Hacking
Exploited Host
Web App Attack
๐ท๐บ
DZBOT
2026-08-25 06:23:02
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
Ha1fdan
2026-08-22 16:52:29
(1 month ago)
{"level":"info","ts":1787417544.5306928,"logger":"http.log.access","msg":"handled request","request" ...
show more
{"level":"info","ts":1787417544.5306928,"logger":"http.log.access","msg":"handled request","request":{"remote_ip":"104.23.223.29","remote_port":"9930","client_ip":"104.23.223.29","proto":"HTTP/2.0","method":"GET","host":"serverhuset.dk","uri":"/inputs.php","headers":{"X-Forwarded-Proto":["https"],"Upgrade-Insecure-Requests":["1"],"Cache-Control":["max-age=0"],"X-Forwarded-For":["20.100.175.163"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"],"Cf-Connecting-Ip":["20.100.175.163"],"Sec-Fetch-Site":["none"],"Accept-Language":["en-US, en; q=0.9"],"Cdn-Loop":["cloudflare; loops=1"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Dnt":["1"],"Cf-Ipcountry":["NO"],"Sec-Ch-Ua-Mobile":["?0"],"Accept":["text/html, application/xhtml+xml, application/xml; q=0.9, image/webp, image/apng, */*; q=0.8, application/signed-exchange; v=b3; q=0.7"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"Accept-Encoding":["gzip, br"],"Sec-Ch-Ua":["\"No
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 06:39:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 02:39:53.069305 2026] [security2:error] [pid 7304:tid 7304] [client 104.23.223.29:13090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pluralmatrix.net"] [uri "/.git/HEAD"] [unique_id "aoVPuQv6FB3eTHvs0NBwWwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 16:14:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 12:14:29.090360 2026] [security2:error] [pid 26257:tid 26257] [client 104.23.223.29:13603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.zabyte.net"] [uri "/.git/HEAD"] [unique_id "aoMzZfk7WYeGTqRdEEWS2gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:45:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:44:59.588412 2026] [security2:error] [pid 24591:tid 24591] [client 104.23.223.29:9743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fairfieldfarms.net"] [uri "/.git/HEAD"] [unique_id "aoLKC6OE1ts6KyJhTHTnJAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack