๐ฉ๐ช
Kreapptivo
2026-06-04 16:07:20
(1 hour ago)
104.23.239.108 - - [04/Jun/2026:18:07:16 +0200] "GET /.git/config HTTP/2.0" 404 8566 "-" "Wget/1.21. ...
show more
104.23.239.108 - - [04/Jun/2026:18:07:16 +0200] "GET /.git/config HTTP/2.0" 404 8566 "-" "Wget/1.21.3 (linux-gnu)"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 01:40:28
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 21:40:24.839959 2026] [security2:error] [pid 7248:tid 7248] [client 104.23.239.108:12752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magusniche.com"] [uri "/.git/config"] [unique_id "aiDXiCQKgi1Gm-37w1rqUAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:00:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:00:39.520184 2026] [security2:error] [pid 7659:tid 7659] [client 104.23.239.108:10171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riccardiagency.com"] [uri "/.git/config"] [unique_id "ah7-J4_wtMyYv_Oba3Ya8QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 10:04:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:04:50.611418 2026] [security2:error] [pid 18241:tid 18241] [client 104.23.239.108:14102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buynorthwest.com"] [uri "/.git/config"] [unique_id "ah6qwkR_VE9UMlOI0TdPBQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 06:53:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 02:53:19.495311 2026] [security2:error] [pid 24208:tid 24208] [client 104.23.239.108:9730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.abcollie.com"] [uri "/.git/config"] [unique_id "ah5938UvIPF9pShV65oaaQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Oakley
2026-05-31 07:59:17
(4 days ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
mnsf
2026-05-29 14:05:05
(6 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-05-21 14:53:46
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-05-15 01:51:11
(2 weeks ago)
2026-05-15T03:51:09.046277+02:00 nimbus sshd[147841]: pam_unix(sshd:auth): authentication failure; l ...
show more
2026-05-15T03:51:09.046277+02:00 nimbus sshd[147841]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.23.239.108 user=root
2026-05-15T03:51:10.640109+02:00 nimbus sshd[147841]: Failed password for root from 104.23.239.108 port 43974 ssh2
...
show less
Brute-Force
SSH
๐ฆ๐บ
trentwiles.com
2026-05-13 22:56:39
(3 weeks ago)
Unauthorized connection attempt detected from IP address 104.23.239.108 to port 443 [SYD]
Port Scan
๐ฆ๐บ
trentwiles.com
2026-05-12 16:18:31
(3 weeks ago)
Unauthorized connection attempt detected from IP address 104.23.239.108 to port 80 [SYD]
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-05-12 05:28:10
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 04:23:05
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:22:50.625616 2026] [security2:error] [pid 15425:tid 15425] [client 104.23.239.108:11106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "high5-vr.com"] [uri "/.env.development.local"] [unique_id "agFZmgogrwevjnXUtA1-AQAAAA0"], referer: https://www.google.com/search?q=high5-vr.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
JustMeHere
2026-05-10 20:52:58
(3 weeks ago)
[Sun May 10 16:52:53.136857 2026] [security2:error] [pid 352895:tid 352931] [client 104.23.239.108:1 ...
show more
[Sun May 10 16:52:53.136857 2026] [security2:error] [pid 352895:tid 352931] [client 104.23.239.108:10523] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "freepbx.yorknation.com"] [uri "/.git/config"] [unique_id "agDwJVlQGUu-eVgvkd9GqQAAAQg"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 03:38:28
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 23:38:23.172413 2026] [security2:error] [pid 17654:tid 17664] [client 104.23.239.108:9568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sea2er.com"] [uri "/.env"] [unique_id "af6sL-eGsypgrTNIHmZ1OQAAAoE"]
show less
Brute-Force
Bad Web Bot
Web App Attack