๐บ๐ธ
TPI-Abuse
2026-09-30 06:47:43
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:47:38.764766 2026] [security2:error] [pid 20052:tid 20052] [client 104.23.223.56:10629] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamroomrecording.com"] [uri "/.git/config"] [unique_id "arywiulCsHUgrwlVF7m8BAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:08:31
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:08:23.814385 2026] [security2:error] [pid 26273:tid 26273] [client 104.23.223.56:13456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "copiershickory.com"] [uri "/.git/config"] [unique_id "arx9J-B8lSn0oR341xFVWAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:16:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:16:26.228739 2026] [security2:error] [pid 30187:tid 30187] [client 104.23.223.56:11322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "articulaterecords.com"] [uri "/.git/config"] [unique_id "arxGyto47gHNjTEoQw2QPgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-29 12:30:43
(1 day ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ง๐ช
madeit
2026-09-29 11:14:45
(1 day ago)
Web App Attack
๐ซ๐ฎ
kumiko
2026-09-26 06:55:42
(4 days ago)
[2026-09-26 09:55:41] Probing for dotfiles
"GET /.git/config HTTP/2.0" 403
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 20:36:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 16:36:06.106530 2026] [security2:error] [pid 13137:tid 13137] [client 104.23.223.56:11115] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "etoyfun.com"] [uri "/.git/config"] [unique_id "arbbNg5eQM2-i9lKCmpf6wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 10:34:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:34:29.032620 2026] [security2:error] [pid 32370:tid 32443] [client 104.23.223.56:11871] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexlogic.com"] [uri "/.git/config"] [unique_id "arZONRRxjcIk4bCHRQt0zAAAAcM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-17 08:55:46
(1 week ago)
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-12 03:32:26
(2 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 5 hits.
show less
Brute-Force
Web App Attack
๐ง๐ช
voormedia
2026-09-08 05:30:55
(3 weeks ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 00:09:16
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:09:09.330614 2026] [security2:error] [pid 21117:tid 21117] [client 104.23.223.56:14020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barpubsigns.com"] [uri "/.git/config"] [unique_id "apoMJXZO_kpOTqu_4_GGywAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-02 02:16:33
(4 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 00:56:33
(4 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ซ๐ท
UnixPrime
2026-08-27 18:12:45
(1 month ago)
104.23.223.56 - - [27/Aug/2026:20:12:43 +0200] "GET /.env.bak HTTP/1.1" 404 118 "-" "crusader-worker ...
show more
104.23.223.56 - - [27/Aug/2026:20:12:43 +0200] "GET /.env.bak HTTP/1.1" 404 118 "-" "crusader-worker/1.0"
104.23.223.56 - - [27/Aug/2026:20:12:43 +0200] "GET /.env.local HTTP/1.1" 404 118 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack