๐ฉ๐ช
wiredalter
2026-09-03 11:53:39
(12 hours ago)
Blocked by UFW on dVPS [8443/tcp]
Source Port: 13463
TTL: 55
Packet Length: 60
TOS: 0x00
Analyzed b ...
show more
Blocked by UFW on dVPS [8443/tcp]
Source Port: 13463
TTL: 55
Packet Length: 60
TOS: 0x00
Analyzed by https://ip.wiredalter.com
show less
Port Scan
Brute-Force
๐ฆ๐บ
paulshipley.com.au
2026-09-01 12:23:51
(2 days ago)
[Tue Sep 01 22:23:50.302801 2026] [security2:error] [pid 247121] [client 104.23.225.133:13039] [clie ...
show more
[Tue Sep 01 22:23:50.302801 2026] [security2:error] [pid 247121] [client 104.23.225.133:13039] [client 104.23.225.133] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/.git/HEAD"] [unique_id "apbD1htjo8ZdFUn4kLRM4wAAAA4"]
...
show less
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-08-30 07:48:11
(4 days ago)
GET /.git/HEAD HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 07:41:23
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 03:41:20.223815 2026] [security2:error] [pid 19966:tid 19966] [client 104.23.225.133:12782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsndetx.com"] [uri "/.git/HEAD"] [unique_id "apPeoH1qEiO6kY4F-jUtfAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 02:39:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 22:39:49.137014 2026] [security2:error] [pid 20157:tid 20157] [client 104.23.225.133:10805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.naominixon.com"] [uri "/.git/config"] [unique_id "apOX9TJxFS2Ne05eEcGdFQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 15:04:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 11:04:04.400645 2026] [security2:error] [pid 8054:tid 8054] [client 104.23.225.133:12596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ondakompun.com"] [uri "/.git/config"] [unique_id "apL05DdQDhhGYRKtYRiGMQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webko.si
2026-08-29 11:30:27
(5 days ago)
JZKK: Bruteforce web app access, URI detail: '/.git/config'.
Web App Attack
Anonymous
2026-08-29 02:38:39
(5 days ago)
GET /.git/config HTTP/1.1
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 08:59:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:59:52.080371 2026] [security2:error] [pid 2690:tid 2690] [client 104.23.225.133:12485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.leonardodecaprio.com"] [uri "/.git/config"] [unique_id "ao_8iOkEqtXH_4z1wxK1gwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 04:58:33
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:07:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:07:24.115764 2026] [security2:error] [pid 28857:tid 28857] [client 104.23.225.133:10440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.compliancedepts.com"] [uri "/.git/config"] [unique_id "ao8dTPFjwrGoO9W1gqf58wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 12:07:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:07:22.533833 2026] [security2:error] [pid 989:tid 989] [client 104.23.225.133:12792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bacona.org"] [uri "/.git/HEAD"] [unique_id "ao7W-gb9vLeIypa0Vi2ZYAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 00:29:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:29:10.997774 2026] [security2:error] [pid 20417:tid 20417] [client 104.23.225.133:10463] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lizinkcreations.needtoorder.us"] [uri "/.git/HEAD"] [unique_id "ao4zVsqwitoeo7KXT1kiewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 23:35:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 19:35:35.376838 2026] [security2:error] [pid 5939:tid 5939] [client 104.23.225.133:9311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.frame-sa.com"] [uri "/.git/HEAD"] [unique_id "ao4mx6ocUdME09w2wiZVPgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-25 22:51:42
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack