Anonymous
2026-07-18 09:53:56
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-16 05:43:23
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2026-07-15 18:52:31
(4 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-07-11 13:17:30
(1 week ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 13:17:00
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 09:16:54.423207 2026] [security2:error] [pid 14402:tid 14402] [client 104.23.225.158:10598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marriedtv.com"] [uri "/.git/config"] [unique_id "akZkxgFXaaVoqioYQMQ2qQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-02 08:06:08
(2 weeks ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐ฌ๐ง
OptimusGO
2026-06-25 10:58:24
(3 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-25 11:58:24 UTC
Log evidence:
104.23.225.158 - - [25/Jun/2026:11:58:21 +0100] "GET /app.tar.gz HTTP/1.1" 404 118 "-" "curl/8.7.1"
06/25/2026-11:58:21.938898 [**] [1:1000115:1] SECURITY CRITICAL: Backup File Access Attempt [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 104.23.225.158:12586 -> 185.127.18.66:80
06/25/2026-11:58:21.938898 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 104.23.225.158:12586 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-23 05:40:11
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 01:40:05.473031 2026] [security2:error] [pid 16187:tid 16187] [client 104.23.225.158:11763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenotarymobile.com"] [uri "/.git/config"] [unique_id "ajocNYxofR6dTGrq4MqmKQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ป๐ช
LUISE
2026-06-18 00:25:31
(1 month ago)
Vulnerability scanning for Web/phpMyAdmin files on ULA server 72-23.
Hacking
Bad Web Bot
๐บ๐ธ
mnsf
2026-06-16 02:05:59
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
micropedro
2026-06-11 10:30:37
(1 month ago)
5 incidents: malicious activity. First: 2026-06-02 12:30, Last: 2026-06-11 06:30 UTC. Triggers: ufw- ...
show more
5 incidents: malicious activity. First: 2026-06-02 12:30, Last: 2026-06-11 06:30 UTC. Triggers: ufw-repeater.
show less
Port Scan
๐บ๐ธ
micropedro
2026-06-11 10:30:06
(1 month ago)
5 incidents: malicious activity. First: 2026-05-19 10:30, Last: 2026-06-11 06:30 UTC. Triggers: ufw- ...
show more
5 incidents: malicious activity. First: 2026-05-19 10:30, Last: 2026-06-11 06:30 UTC. Triggers: ufw-repeater.
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-08 18:01:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:01:25.916256 2026] [security2:error] [pid 7276:tid 7282] [client 104.23.225.158:12777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jupitermaturin.com.venezuelaguia.com"] [uri "/.git/config"] [unique_id "aicDdYxdjp2NQDXFnbmbnAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
micropedro
2026-05-26 15:30:15
(1 month ago)
3 incidents: malicious activity. First: 2026-05-19 10:30, Last: 2026-05-26 11:30 UTC. Triggers: ufw- ...
show more
3 incidents: malicious activity. First: 2026-05-19 10:30, Last: 2026-05-26 11:30 UTC. Triggers: ufw-repeater.
show less
Port Scan
๐บ๐ธ
micropedro
2026-05-12 13:30:04
(2 months ago)
5 incidents: web scanning/attack. First: 2026-05-12 08:49, Last: 2026-05-12 09:30 UTC. Triggers: non ...
show more
5 incidents: web scanning/attack. First: 2026-05-12 08:49, Last: 2026-05-12 09:30 UTC. Triggers: non-public-port,port-trap,firewall-http,ufw-repeater,recidive.
show less
Port Scan
Brute-Force
Web App Attack