๐บ๐ธ
OceanTreasure
2026-06-16 13:15:06
(5 hours ago)
tcp/80; Git configuration exposure attempt: "GET /.git/config" @ 2026-06-16T13:11:57Z [proxy]
Web App Attack
๐บ๐ธ
xmission.com
2026-06-16 08:09:03
(10 hours ago)
Blocked by UFW (TCP on 51726)
Source port: 9000
TTL: 48
Packet length: 76
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 51726)
Source port: 9000
TTL: 48
Packet length: 76
TOS: 0x08
This report (for 104.223.84.121) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
LRob.fr
2026-06-16 05:00:23
(13 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ท
tilellit.pro
2026-06-16 04:25:34
(14 hours ago)
Fail2Ban banned 104.223.84.121 for security violations in jail wp-armour. Log: 2026/06/16 04:25:34 [ ...
show more
Fail2Ban banned 104.223.84.121 for security violations in jail wp-armour. Log: 2026/06/16 04:25:34 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 104.223.84.121 | Target: wplogin" , client: 104.223.84.121, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED]
...
show less
Web Spam
๐ฆ๐บ
screwlooseit.com.au
2026-06-15 23:03:09
(19 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/104-223-84-121-host.colocrossing.com
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 22:00:05
(20 hours ago)
Auto-ban: >3000 req/min op 2026-06-15
Web App Attack
SSH
Hacking
๐บ๐ธ
oncord
2026-06-15 06:38:06
(1 day ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-14 19:31:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.223.84.121 (104-223-84-121-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 104.223.84.121 (104-223-84-121-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 15:31:30.515046 2026] [security2:error] [pid 25152:tid 25152] [client 104.223.84.121:17506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.villagestoner.com"] [uri "/.git/config"] [unique_id "ai8BkuMbGLGMsTGCoJ9OPAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 15:23:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.223.84.121 (104-223-84-121-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 104.223.84.121 (104-223-84-121-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:23:36.697560 2026] [security2:error] [pid 31232:tid 31232] [client 104.223.84.121:55912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.armstrongpartnersllc.com"] [uri "/.git/config"] [unique_id "ai7HeBHEm7iTBTb501PK0wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 11:43:09
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 104.223.84.121 (104-223-84-121-host.colocrossin ...
show more
(mod_security) mod_security (id:225170) triggered by 104.223.84.121 (104-223-84-121-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 07:43:04.118803 2026] [security2:error] [pid 8089:tid 8089] [client 104.223.84.121:63384] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||luxandunion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "luxandunion.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ai6TyMA-PH-padmvTolimwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TNZ
2026-06-13 22:06:59
(2 days ago)
Automated honeypot: attack_tool:go-http | Path: /.git/config | ISP: AS36352 HostPapa | ASN: AS36352 ...
show more
Automated honeypot: attack_tool:go-http | Path: /.git/config | ISP: AS36352 HostPapa | ASN: AS36352 HostPapa [TOR] [HOSTING] | Abuse score: 48 | Open ports: [] | UA: Go-http-client/1.1
show less
Web App Attack
๐บ๐ธ
xmission.com
2026-06-13 20:16:33
(2 days ago)
Blocked by UFW (TCP on 34824)
Source port: 9100
TTL: 51
Packet length: 76
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 34824)
Source port: 9100
TTL: 51
Packet length: 76
TOS: 0x08
This report (for 104.223.84.121) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-06-13 14:40:54
(3 days ago)
104.223.84.121 - - [13/Jun/2026:16:40:54 +0200] "GET /product-category/marke/body-attack/ HTTP/1.1" ...
show more
104.223.84.121 - - [13/Jun/2026:16:40:54 +0200] "GET /product-category/marke/body-attack/ HTTP/1.1" 200 64811 "https:///.git/config" "Go-http-client/1.1"
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-13 04:43:07
(3 days ago)
Try to access /xmlrpc.php
Web App Attack
๐จ๐ญ
ca
2026-06-12 23:21:14
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot