πΉπ·
ScchutzZ
2026-10-08 22:05:08
(1 day ago)
Fail2Ban banΔ±. Jail: plesk-modsecurity.
Brute-Force
π§πͺ
madeit
2026-10-08 09:51:21
(1 day ago)
Web App Attack
π©πͺ
brechtr
2026-10-07 17:09:55
(2 days ago)
[Press84-BanHammer] bad username β Sourced from: press84.com β Request: POST /wp-login.php
Brute-Force
π«π·
dynamix
2026-10-05 19:48:42
(4 days ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 15:57:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 11:57:20.031516 2026] [security2:error] [pid 31519:tid 31519] [client 104.23.225.3:9621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sympalais.com"] [uri "/.git/config"] [unique_id "asPI4KAVfveGPsLzNSyZjQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-10-04 21:21:12
(5 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-09-18 01:26:06
(3 weeks ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-17 22:48:56
(3 weeks ago)
IP matched detection query many 3xx errors.
Brute-Force
π§πͺ
madeit
2026-09-14 09:22:09
(3 weeks ago)
Web App Attack
π³π±
overture.bar
2026-09-02 10:33:10
(1 month ago)
Blocked by UFW on NsmallFE [8443/tcp] | SPT: 9432 | TTL: 53 | LEN: 60 | TOS: 0x00
Port Scan
πΊπΈ
TPI-Abuse
2026-09-01 01:01:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:01:25.706935 2026] [security2:error] [pid 31905:tid 31905] [client 104.23.225.3:9318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beautyradio.com"] [uri "/.git/config"] [unique_id "apYj5WsvKke0YHsMiq9KhgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 13:22:47
(1 month ago)
104.23.225.3 - - [31/Aug/2026:15:22:46 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
104.23.225.3 - - [31/Aug/2026:15:22:46 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.3 - - [31/Aug/2026:15:22:46 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.3 - - [31/Aug/2026:15:22:46 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.3 - - [31/Aug/2026:15:22:47 +0200] "GET //2018/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.3 - - [31/Aug/2026:15:22:47 +0200] "GET //shop/wp-includes/wlwmanifest.xml HTTP/1.
...
show less
Brute-Force
Web App Attack
π©πͺ
Starburst SysOp Team
2026-08-29 00:38:15
(1 month ago)
(CT) IP 104.23.225.3 (FR/France/Paris Department/Paris/-/[AS13335 Cloudflare, Inc.]) found to have 1 ...
show more
(CT) IP 104.23.225.3 (FR/France/Paris Department/Paris/-/[AS13335 Cloudflare, Inc.]) found to have 124 connections (0-nue6-2)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-28 08:07:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:07:09.275677 2026] [security2:error] [pid 30646:tid 30646] [client 104.23.225.3:11578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.samanthasomers.com"] [uri "/.git/HEAD"] [unique_id "apFBrSLChTpC7oZhhRgdngAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 04:43:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:43:48.353209 2026] [security2:error] [pid 30460:tid 30460] [client 104.23.225.3:11855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.akramansari.com"] [uri "/.git/HEAD"] [unique_id "apESBCad5CYV_1gOY-ftHgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack