πΊπΈ
TPI-Abuse
2026-03-18 08:23:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 04:23:15.265926 2026] [security2:error] [pid 16258:tid 16258] [client 104.23.239.136:12954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bayareamustangs.com"] [uri "/.env.orig"] [unique_id "abpg8y_JS_HMU4YVdDidAAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
gadix
2026-03-18 08:22:01
(2 months ago)
[18/Mar/2026:09:21:19.018554 +0100] abpgf3MuqijIFNJxiumH-gAAAFg 104.23.239.136 51710 127.0.0.1 7081
...
show more
[18/Mar/2026:09:21:19.018554 +0100] abpgf3MuqijIFNJxiumH-gAAAFg 104.23.239.136 51710 127.0.0.1 7081
[18/Mar/2026:09:21:19.019379 +0100] abpgf3MuqijIFNJxiumH-wAAAFA 104.23.239.136 51716 127.0.0.1 7081
[18/Mar/2026:09:22:00.331981 +0100] abpgqHMuqijIFNJxiumIOwAAAEI 104.23.239.136 50430 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-03-18 00:50:05
(2 months ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-03-17 19:46:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 17 15:46:52.256917 2026] [security2:error] [pid 8231:tid 8231] [client 104.23.239.136:13163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thepianosmith.com"] [uri "/.git/config"] [unique_id "abmvrLUbVODhfj3fOK_7MgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-03-17 06:08:49
(2 months ago)
Scanning/Probing (52)
Brute-Force
Web App Attack
π©πͺ
acadeova
2026-03-17 04:34:22
(2 months ago)
π¨ Recon detected (nft drop)
SRC=104.23.239.136
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
π¨ Recon detected (nft drop)
SRC=104.23.239.136
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-03-16 11:14:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 07:14:48.269606 2026] [security2:error] [pid 29635:tid 29635] [client 104.23.239.136:13209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flymarlin.com"] [uri "/.git/config"] [unique_id "abfmKFlsMjuDdq3n5NX4TQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-15 10:22:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 06:22:53.722549 2026] [security2:error] [pid 1532:tid 1532] [client 104.23.239.136:9707] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.digi-estudio.com"] [uri "/.git/HEAD"] [unique_id "abaIffA2uucjUeyaiGlTcwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-15 09:46:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 05:46:23.559723 2026] [security2:error] [pid 4531:tid 4653] [client 104.23.239.136:14103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.charliefranks.com"] [uri "/.git/HEAD"] [unique_id "abZ_72XtYJEd5hCQ692AuAAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 17:49:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 13:49:10.551989 2026] [security2:error] [pid 16484:tid 16484] [client 104.23.239.136:11546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.daretownkindling.com"] [uri "/.git/HEAD"] [unique_id "abWfluQHIYy9naFtVxUlOwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 17:20:50
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 13:20:45.055710 2026] [security2:error] [pid 25617:tid 25617] [client 104.23.239.136:10001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catholicshopper.com"] [uri "/.git/config"] [unique_id "abWY7b3E2g9jTIYOFsz3KAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 09:03:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 05:03:49.985210 2026] [security2:error] [pid 31294:tid 31294] [client 104.23.239.136:10481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dogandponyband.com"] [uri "/.git/HEAD"] [unique_id "abUkdRZN5-29GoL0Apxj5QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 07:25:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 03:25:52.479441 2026] [security2:error] [pid 16679:tid 16679] [client 104.23.239.136:13836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.von-s.com"] [uri "/.git/config"] [unique_id "abUNgLXzaF1qCyZdFnDBfwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 03:06:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 23:06:08.614367 2026] [security2:error] [pid 26482:tid 26508] [client 104.23.239.136:10329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalacademyoffinancialmanagement.com.aafm.us"] [uri "/.git/HEAD"] [unique_id "abTQoOZu6TU-44Q3iFb0SwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-13 16:49:28
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 12:48:42.857118 2026] [security2:error] [pid 26608:tid 26608] [client 104.23.239.136:14039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.venture2-22.org"] [uri "/.git/config"] [unique_id "abQ_6vaT0iEYQKo9unxFiwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack