๐ซ๐ท
dynamix
2026-09-20 13:52:35
(1 hour ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-17 23:41:31
(2 days ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ซ๐ท
dynamix
2026-09-17 12:05:58
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dynamix
2026-09-12 08:38:07
(1 week ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-08 19:33:31
(1 week ago)
Web scanner: GET /.git/config
Web App Attack
Hacking
๐ซ๐ฎ
habs
2026-09-08 16:25:40
(1 week ago)
104.23.225.5 - - [08/Sep/2026:19:25:39 +0300] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 162 "- ...
show more
104.23.225.5 - - [08/Sep/2026:19:25:39 +0300] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 162 "-" "http://koiranpeti.eu/wp-admin/install.php?step=1"
...
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-08 12:10:44
(1 week ago)
[Tue Sep 08 22:10:43.363273 2026] [security2:error] [pid 242853] [client 104.23.225.5:10716] [client ...
show more
[Tue Sep 08 22:10:43.363273 2026] [security2:error] [pid 242853] [client 104.23.225.5:10716] [client 104.23.225.5] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/.git/config"] [unique_id "ap_7QxtF2a1SWeQ8Tu_p-gAAAAo"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 15:59:45
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:59:41.588175 2026] [security2:error] [pid 9295:tid 9318] [client 104.23.225.5:9892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "annastasiamason.com"] [uri "/.git/HEAD"] [unique_id "apWk7U9d2v7zX0P179cpggAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 12:57:36
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:57:32.150274 2026] [security2:error] [pid 8340:tid 8340] [client 104.23.225.5:12621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barkoskieelectric.com"] [uri "/.git/config"] [unique_id "apV6PK20hvjvSxF-8mKvrAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-08-30 06:31:10
(3 weeks ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/HEAD. Blocked at ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/HEAD. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-29 19:09:30
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 15:09:22.883786 2026] [security2:error] [pid 15855:tid 15855] [client 104.23.225.5:9629] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.djmrmusic.com"] [uri "/.git/HEAD"] [unique_id "apMuYpAj1OawOfT-Naq_2AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 12:56:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:55:59.142977 2026] [security2:error] [pid 1752:tid 1752] [client 104.23.225.5:12662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amybeam.info"] [uri "/.git/HEAD"] [unique_id "apLW3xwLo8RI2CI3a7n_DQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 08:47:55
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:47:50.360225 2026] [security2:error] [pid 28359:tid 28359] [client 104.23.225.5:9263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdpeters.com"] [uri "/.git/HEAD"] [unique_id "apKctkaeLxzr1g7Pm7eOZgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-29 06:44:04
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-28 17:23:02
(3 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan