๐ฌ๐ง
OptimusGO
2026-06-27 23:41:01
(1 day ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-28 00:41:01 UTC
Log evidence:
104.23.225.41 - - [28/Jun/2026:00:41:00 +0100] "GET /js/secrets/aws-exports.js HTTP/1.1" 404 118 "-" "curl/8.7.1"
06/28/2026-00:41:00.016727 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 104.23.225.41:13622 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
Anonymous
2026-06-26 17:53:29
(2 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ง๐พ
lns.bz
2026-06-23 19:17:54
(5 days ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 07:17:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 03:17:04.128188 2026] [security2:error] [pid 32728:tid 32728] [client 104.23.225.41:11267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fxbgsanta.com"] [uri "/.git/config"] [unique_id "ajD4cC1tV0k6gUqI6s_aRAAAAGw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 17:58:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:58:19.647219 2026] [security2:error] [pid 3103:tid 3127] [client 104.23.225.41:12883] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iguanablue.newleafpro.com"] [uri "/.git/config"] [unique_id "aicCu1cAOpUAru892EfQQQAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 12:46:25
(1 month ago)
invalid request
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-03-20 19:12:49
(3 months ago)
104.23.225.41 - - [20/Mar/2026:20:12:48 +0100] "GET /vendor/drupal/coder/.git/info/exclude HTTP/1.1" ...
show more
104.23.225.41 - - [20/Mar/2026:20:12:48 +0100] "GET /vendor/drupal/coder/.git/info/exclude HTTP/1.1" 404 13 "-" "curl/8.7.1" "ip.pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ps-center
2026-02-24 16:02:46
(4 months ago)
SS1: Web Attack GET /wp-content/plugins/hellopress/wp_filemanager.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2026-02-21 22:29:02
(4 months ago)
SS1: Web Attack GET /wp-content/plugins/hellopress/wp_filemanager.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-02-16 08:32:51
(4 months ago)
[Mon Feb 16 09:32:38.743169 2026] [authz_core:error] [pid 22029] [client 104.23.225.41:10718] AH0163 ...
show more
[Mon Feb 16 09:32:38.743169 2026] [authz_core:error] [pid 22029] [client 104.23.225.41:10718] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Feb 16 09:32:38.888028 2026] [authz_core:error] [pid 22029] [client 104.23.225.41:10718] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Feb 16 09:32:49.604463 2026] [authz_core:error] [pid 10455] [client 104.23.225.41:10056] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-02-11 13:46:14
(4 months ago)
[Wed Feb 11 14:46:08.242706 2026] [authz_core:error] [pid 8471] [client 104.23.225.41:11070] AH01630 ...
show more
[Wed Feb 11 14:46:08.242706 2026] [authz_core:error] [pid 8471] [client 104.23.225.41:11070] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Feb 11 14:46:13.977530 2026] [authz_core:error] [pid 7596] [client 104.23.225.41:11118] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Feb 11 14:46:14.051346 2026] [authz_core:error] [pid 7596] [client 104.23.225.41:11118] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-02-07 17:48:26
(4 months ago)
[Sat Feb 07 18:48:24.524797 2026] [authz_core:error] [pid 1848] [client 104.23.225.41:11216] AH01630 ...
show more
[Sat Feb 07 18:48:24.524797 2026] [authz_core:error] [pid 1848] [client 104.23.225.41:11216] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://wolfgang-eitel.de
[Sat Feb 07 18:48:24.917681 2026] [authz_core:error] [pid 1848] [client 104.23.225.41:11216] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://wolfgang-eitel.de
[Sat Feb 07 18:48:25.367178 2026] [authz_core:error] [pid 1848] [client 104.23.225.41:11216] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://wolfgang-eitel.de
...
show less
Web App Attack
Anonymous
2026-01-23 10:35:46
(5 months ago)
[Fri Jan 23 11:35:45.565318 2026] [authz_core:error] [pid 21519] [client 104.23.225.41:9850] AH01630 ...
show more
[Fri Jan 23 11:35:45.565318 2026] [authz_core:error] [pid 21519] [client 104.23.225.41:9850] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Jan 23 11:35:45.664084 2026] [authz_core:error] [pid 21519] [client 104.23.225.41:9850] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Jan 23 11:35:45.760223 2026] [authz_core:error] [pid 21519] [client 104.23.225.41:9850] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-01-22 08:50:36
(5 months ago)
[Thu Jan 22 09:50:35.842232 2026] [authz_core:error] [pid 21610] [client 104.23.225.41:13987] AH0163 ...
show more
[Thu Jan 22 09:50:35.842232 2026] [authz_core:error] [pid 21610] [client 104.23.225.41:13987] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Jan 22 09:50:35.863700 2026] [authz_core:error] [pid 21610] [client 104.23.225.41:13987] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Jan 22 09:50:35.884626 2026] [authz_core:error] [pid 21610] [client 104.23.225.41:13987] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-01-22 02:44:03
(5 months ago)
[Thu Jan 22 03:42:01.085054 2026] [authz_core:error] [pid 7560] [client 104.23.225.41:9501] AH01630: ...
show more
[Thu Jan 22 03:42:01.085054 2026] [authz_core:error] [pid 7560] [client 104.23.225.41:9501] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Jan 22 03:44:03.048607 2026] [authz_core:error] [pid 7560] [client 104.23.225.41:13302] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Jan 22 03:44:03.070669 2026] [authz_core:error] [pid 7560] [client 104.23.225.41:13302] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack