๐บ๐ธ
TPI-Abuse
2026-06-21 07:05:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 03:05:44.485018 2026] [security2:error] [pid 13439:tid 13439] [client 104.23.239.9:13864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.geo-modal.nodepot.com"] [uri "/.env.backup"] [unique_id "ajeNSIJGfvxHYHal5hmehQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
Prcek
2026-06-20 16:57:18
(2 days ago)
PortScan:HOST=104.23.239.9,DPORTS=443
Port Scan
๐ณ๐ด
jad-abuse
2026-06-10 17:50:36
(1 week ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Ob ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:33:00
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:32:55.971275 2026] [security2:error] [pid 5237:tid 5237] [client 104.23.239.9:11172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buffalowedding.buffaloweddingdeejay.com"] [uri "/.git/config"] [unique_id "aicY5wrCEFh4O-z3_7dufwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 05:09:14
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 01:09:10.905067 2026] [security2:error] [pid 11625:tid 11625] [client 104.23.239.9:9252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "computergeek.us"] [uri "/.git/config"] [unique_id "aiT89mImKMhIdRVjIhOe0QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 05:23:16
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 01:23:13.101609 2026] [security2:error] [pid 3131:tid 3131] [client 104.23.239.9:11798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robotrodeo.net"] [uri "/.git/config"] [unique_id "aiELwX202RrhJbjOeYrg_wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 00:16:55
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 20:16:49.654925 2026] [security2:error] [pid 6902:tid 6902] [client 104.23.239.9:10502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smid.tv"] [uri "/.git/config"] [unique_id "aiDD8U3hU8lH6kkXFeyWqwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 18:14:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 14:14:47.411094 2026] [security2:error] [pid 10414:tid 10414] [client 104.23.239.9:12342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marcelacalvet.com"] [uri "/.git/config"] [unique_id "ah8dl00E__BRFtRnMyYq_gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 11:06:43
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 07:06:38.762483 2026] [security2:error] [pid 20651:tid 20651] [client 104.23.239.9:9350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "disio.com"] [uri "/.git/config"] [unique_id "ah65Pmqwo8XN_l286vJLTwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 08:50:58
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 04:50:53.623428 2026] [security2:error] [pid 27926:tid 27926] [client 104.23.239.9:11677] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agapeaccounting.com"] [uri "/.git/config"] [unique_id "ah6ZbdRigCetv7HKdP9IPQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 08:06:47
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-29 22:06:30
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-28.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-23 04:12:45
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 00:12:40.507589 2026] [security2:error] [pid 29614:tid 29614] [client 104.23.239.9:11030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matthewhestad.help"] [uri "/.git/config"] [unique_id "ahEpOMQIjjrGyEl7wCvwbwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-21 03:13:58
(1 month ago)
(caddyscan) Scanner path probe from 104.23.239.9 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.23.239.9 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.239.9 - - [21/May/2026:02:33:40 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.239.9 - - [21/May/2026:02:39:38 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.239.9 - - [21/May/2026:02:41:05 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.239.9 - - [21/May/2026:03:08:34 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.239.9 - - [21/May/2026:03:13:56 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐ท๐บ
DZBOT
2026-05-20 22:04:42
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack