๐บ๐ธ
TPI-Abuse
2026-08-27 02:51:45
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 22:51:38.223834 2026] [security2:error] [pid 8577:tid 8580] [client 104.23.225.154:11457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boatservices.boatservicesgroup.com"] [uri "/.git/config"] [unique_id "ao-mOtO7LrYgHfe33d_ILAAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-08-26 10:33:37
(19 hours ago)
web exploits
Hacking
Exploited Host
Web App Attack
Anonymous
2026-08-26 07:02:04
(22 hours ago)
104.23.225.154 - - [26/Aug/2026:09:02:03 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 ...
show more
104.23.225.154 - - [26/Aug/2026:09:02:03 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.154 - - [26/Aug/2026:09:02:03 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.154 - - [26/Aug/2026:09:02:04 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.154 - - [26/Aug/2026:09:02:04 +0200] "GET /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.154 - - [26/Aug/2026:09:02:04 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 04:09:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 00:09:36.713899 2026] [security2:error] [pid 6553:tid 6553] [client 104.23.225.154:11324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.g-drome.com"] [uri "/.git/config"] [unique_id "ao5nAIS8JiveDI2FO3LQ2QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 02:06:34
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ฉ๐ช
Grossmann-Gruppe
2026-08-26 00:30:39
(1 day ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-24 10:25:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 06:25:35.443339 2026] [security2:error] [pid 27517:tid 27517] [client 104.23.225.154:13342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rkm.biz"] [uri "/.git/config"] [unique_id "aowcH4NXTQw9YEV2wVFoVQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-24 09:59:44
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 04:21:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:20:57.668881 2026] [security2:error] [pid 13883:tid 13883] [client 104.23.225.154:11451] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.general.graphics"] [uri "/.git/config"] [unique_id "aovGqU84NZyll8B63J8HUAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-23 12:52:53
(3 days ago)
[23/Aug/2026:15:52:52 +0300] -- 104.23.225.154 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[23/Aug/2026:15:52:52 +0300] -- 104.23.225.154 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 06:55:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 02:55:21.661219 2026] [security2:error] [pid 18061:tid 18061] [client 104.23.225.154:12018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dillydallyvalley.com"] [uri "/.git/config"] [unique_id "aoqZWUwp7SZvyL5DOT4A2QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 01:04:15
(4 days ago)
Http Port:80 (http_status:404) - Agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/201 ...
show more
Http Port:80 (http_status:404) - Agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 19:18:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:18:35.801879 2026] [security2:error] [pid 20504:tid 20504] [client 104.23.225.154:10532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.innovacionesnimba.com"] [uri "/.git/HEAD"] [unique_id "aon2C9dNvFtZO5h-JViSOwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 18:18:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 14:18:42.306799 2026] [security2:error] [pid 12378:tid 12378] [client 104.23.225.154:11105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.advantage-plus.net"] [uri "/.git/HEAD"] [unique_id "aonoAp9FRNFH6DFq6dHXEQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 06:39:33
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:39:26.877566 2026] [security2:error] [pid 25475:tid 25475] [client 104.23.225.154:9561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.irishsetterclubofseattle.com"] [uri "/.git/HEAD"] [unique_id "aolEHkpIT6H5ltrhtWXZUgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack