🇿🇦
conure.sh
2026-08-08 12:07:30
(1 month ago)
csagent: score 21.8: 404 noise floor x7, secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇮🇹
CoreTech srl
2026-08-08 04:43:56
(1 month ago)
cloudlinux2 fail2ban: 2026-08-08 06:39:51,018 fail2ban.actions [1467]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-08 06:39:51,018 fail2ban.actions [1467]: NOTICE [plesk-modsecurity] Unban 34.145.125.41cloudlinux2 fail2ban: 2026-08-08 06:40:28,280 fail2ban.actions [1467]: NOTICE [plesk-modsecurity] Unban 34.138.85.198cloudlinux2 fail2ban: 2026-08-08 06:40:46,248 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 20.215.185.25 - 2026-08-08 06:40:46cloudlinux2 fail2ban: 2026-08-08 06:40:59,532 fail2ban.actions [1467]: NOTICE [plesk-modsecurity] Unban 167.86.149.136cloudlinux2 fail2ban: 2026-08-08 06:41:46,954 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 168.119.91.14 - 2026-08-08 06:41:46cloudlinux2 fail2ban: 2026-08-08 06:42:46,242 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 104.154.228.246 - 2026-08-08 06:42:46cloudlinux2 fail2ban: 2026-08-08 06:42:46,235 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 104.154.228.246 - 2026-08-08 06:42:46cloudlinux2 fail2ban: 2026-08-08 06:42:46,263 fail2ban.f
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-08-08 04:19:56
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 00:19:51.906340 2026] [security2:error] [pid 2839537:tid 2839537] [client 104.154.228.246:51188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amaia.biz"] [uri "/production/.env"] [unique_id "anauZw71IiZ1rrp0XbtmsAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-08 03:50:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:50:08.537736 2026] [security2:error] [pid 3074219:tid 3074219] [client 104.154.228.246:56012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m.gilasoft.biz"] [uri "/.git/config"] [unique_id "anancNo9bZtCULClf-tQ6wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-08-08 03:33:45
(1 month ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-08 03:17:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:16:58.702204 2026] [security2:error] [pid 464710:tid 464710] [client 104.154.228.246:40498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.igpcloud.biz"] [uri "/.git/config"] [unique_id "anafqpk3uf9whWwfP-1y8wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
ochanoko
2026-08-08 01:52:48
(1 month ago)
2026-08-08T10:52:46.923475+09:00 vm-67b67c06-8f nginx[12126]: vm-67b67c06-8f nginx: 2026/08/08 10:52 ...
show more
2026-08-08T10:52:46.923475+09:00 vm-67b67c06-8f nginx[12126]: vm-67b67c06-8f nginx: 2026/08/08 10:52:46 [error] 12126#12126: *60175 access forbidden by rule, client: 104.154.228.246, server: mail.ochanoko.biz, request: "GET /.mcp.json HTTP/2.0", host: "mail.ochanoko.biz"
2026-08-08T10:52:47.118037+09:00 vm-67b67c06-8f nginx[12126]: vm-67b67c06-8f nginx: 2026/08/08 10:52:47 [error] 12126#12126: *60175 access forbidden by rule, client: 104.154.228.246, server: mail.ochanoko.biz, request: "GET /.bashrc HTTP/2.0", host: "mail.ochanoko.biz"
2026-08-08T10:52:47.250176+09:00 vm-67b67c06-8f nginx[12126]: vm-67b67c06-8f nginx: 2026/08/08 10:52:47 [error] 12126#12126: *60175 access forbidden by rule, client: 104.154.228.246, server: mail.ochanoko.biz, request: "GET /.well-known/jwks.json HTTP/2.0", host: "mail.ochanoko.biz"
2026-08-08T10:52:47.286241+09:00 vm-67b67c06-8f nginx[12126]: vm-67b67c06-8f nginx: 2026/08/08 10:52:47 [error] 12126#12126: *60175 access forbidden by rule, client: 104.154.
...
show less
Brute-Force
🇨🇭
4server
2026-08-08 00:27:01
(1 month ago)
[SatAug0802:26:54.0997732026][security2:error][pid289400:tid289595][client104.154.228.246:0]ModSecur ...
show more
[SatAug0802:26:54.0997732026][security2:error][pid289400:tid289595][client104.154.228.246:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"4host.biz\"][uri\"/.git/config\"][unique_id\"anZ3zoKIdJ0lCg8y8h5b4gAAARE\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 22:39:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 18:39:23.542273 2026] [security2:error] [pid 1449939:tid 1449939] [client 104.154.228.246:35216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.angove.biz"] [uri "/.git/config"] [unique_id "anZem-WoXcPqwIT7ApLR6QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-08-07 22:24:01
(1 month ago)
csagent: score 21.6: 404 noise floor x7, secrets grab x2; 2 domain(s) in 6s
Web App Attack
🇧🇪
cmbplf
2026-08-07 22:11:03
(1 month ago)
5.761 requests from abuseipdb.com blacklisted IP (5mos4w13h)
Brute-Force
Bad Web Bot
🇳🇱
Site.eu
2026-08-07 21:41:50
(1 month ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-08-07 21:25:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 17:25:12.402996 2026] [security2:error] [pid 544884:tid 544884] [client 104.154.228.246:42724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jonnyonthespot.biz"] [uri "/.env.local"] [unique_id "anZNOKjjgAWdo_CVigxmSgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 20:25:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.228.246 (246.228.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 16:25:04.844871 2026] [security2:error] [pid 3092253:tid 3092253] [client 104.154.228.246:48740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vn-hakunabtanaguan.biz"] [uri "/.env.production"] [unique_id "anY_IKDIjSfYYZo6NJZGRAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
beon
2026-08-07 20:22:52
(1 month ago)
[DateTime=>2026-08-07T20:22:52Z to 2026-08-08T02:11:37Z (UTC)] , [HoneyPot_Hits=>760 times] , [Honey ...
show more
[DateTime=>2026-08-07T20:22:52Z to 2026-08-08T02:11:37Z (UTC)] , [HoneyPot_Hits=>760 times] , [HoneyPots=>/.aws/config, /.git/config, /.env, /.aws/credentials, /wp-json, /.git-credentials and others] , [irregular_query_Hits=>12 times] , [404targets=>/z9x8c7v6b5-debug-trigger-shingetsu.be-on.biz, /sw.js, /_debugbar/open, /_profiler/open, /api/settings, /service-worker.js and others] , [total_Hits=>912 times] , [Keyword=>WordPress, .well-known, PHP web shells, irregular query]
show less
Bad Web Bot
Web App Attack
Hacking