๐ฉ๐ช
ecs.ge
2026-10-01 16:01:56
(1 day ago)
Automatic Fail2Ban report from jail plesk-panel: multiple matching events detected.
Brute-Force
๐ซ๐ท
dynamix
2026-10-01 15:46:31
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:40:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:39:58.375950 2026] [security2:error] [pid 24364:tid 24364] [client 104.23.225.101:11756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "streetcornerfranchise.com"] [uri "/.git/config"] [unique_id "arzY7kqUg4Ur-KABDhPYVAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:10:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:10:06.627871 2026] [security2:error] [pid 6167:tid 6167] [client 104.23.225.101:9468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "khovanov.com"] [uri "/.git/config"] [unique_id "aryLnvnsuAznBdp3MEjvQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Webmestre
2026-09-29 12:03:00
(3 days ago)
Massive attempt to access non-existent PHP and WordPress pages with different IP /.env /wp-admin/
Bad Web Bot
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-29 09:56:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 05:56:37.385822 2026] [security2:error] [pid 12506:tid 12506] [client 104.23.225.101:10689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.anniversarynapkins.com"] [uri "/.git/config"] [unique_id "aruLVX8qb7wRBwABH5Ew6gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 12:49:21
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-11 08:48:20
(3 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-30 20:22:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:22:39.092687 2026] [security2:error] [pid 10812:tid 10812] [client 104.23.225.101:10508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horseillustration.com"] [uri "/.git/config"] [unique_id "apSRD8eGYErY7jAnX5-fHgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 21:42:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 17:42:27.733726 2026] [security2:error] [pid 26472:tid 26562] [client 104.23.225.101:11567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.switchbl8.nl"] [uri "/.git/HEAD"] [unique_id "apNSQ1kU1uoElKHRxZ9XZgAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-29 06:24:09
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:34:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:34:28.099748 2026] [security2:error] [pid 21271:tid 21271] [client 104.23.225.101:12661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sarawatt.com"] [uri "/.git/HEAD"] [unique_id "apIM9LhE0tbbygwvlHmo-gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:51:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:51:31.120814 2026] [security2:error] [pid 10926:tid 11049] [client 104.23.225.101:12389] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indianfinanceinstitute.com.aafm.us"] [uri "/.git/config"] [unique_id "apGgc_GPHurkhAyzlliYdAAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:15:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:15:35.743195 2026] [security2:error] [pid 1527:tid 1527] [client 104.23.225.101:11551] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.puckerbuttbikini.com"] [uri "/.git/HEAD"] [unique_id "apFt16oHAxXCzXOcp0taRwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 07:50:20
(1 month ago)
[28/Aug/2026:10:50:20 +0300] -- 104.23.225.101 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[28/Aug/2026:10:50:20 +0300] -- 104.23.225.101 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack