๐บ๐ธ
TPI-Abuse
2026-10-10 02:49:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net) ...
show more
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 22:49:38.537159 2026] [security2:error] [pid 26902:tid 26902] [client 104.161.37.234:7967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "socialstudiesforkids.com"] [uri "/var/www/.env"] [unique_id "asmnwkrgSeyxH9ggsv4tHgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-10-09 17:50:39
(10 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐ธ๐ฌ
anotherwatcher
2026-10-09 14:37:58
(13 hours ago)
bad bot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 14:18:06
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net) ...
show more
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 10:18:02.277169 2026] [security2:error] [pid 3030:tid 3030] [client 104.161.37.234:49364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acquivest.net"] [uri "/var/www/.env"] [unique_id "asj3ms5XRHWW_O2_uBiSIQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-09 13:08:02
(15 hours ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [ice01,ice02,mx02,wa01,wa ...
show more
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [ice01,ice02,mx02,wa01,wa02]
show less
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-10-09 09:35:51
(18 hours ago)
Flagged as abuse by IisGuard automated detection (tier L3, score 66/100). Reasons: Reputation=1, Bad ...
show more
Flagged as abuse by IisGuard automated detection (tier L3, score 66/100). Reasons: Reputation=1, BadPath=24,8, Rate=20, Diversity=19,8.
show less
Web App Attack
DDoS Attack
Bad Web Bot
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-09 07:07:59
(21 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 05:29:45
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net) ...
show more
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:29:39.131717 2026] [security2:error] [pid 25676:tid 25676] [client 104.161.37.234:12810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitality-web.com"] [uri "/var/www/.env"] [unique_id "ash7w3wR-k-h9HGT88dxRgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-10-09 01:02:12
(1 day ago)
104.161.37.234 - - [09/Oct/2026:01:02:05 +0000] "GET /aura-29lx1amkv1onlegq79dax5jj.txt HTTP/1.1" 40 ...
show more
104.161.37.234 - - [09/Oct/2026:01:02:05 +0000] "GET /aura-29lx1amkv1onlegq79dax5jj.txt HTTP/1.1" 404 32446 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
104.161.37.234 - - [09/Oct/2026:01:02:07 +0000] "GET /asset-manifest.json HTTP/1.1" 404 26398 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
104.161.37.234 - - [09/Oct/2026:01:02:08 +0000] "GET /mix-manifest.json HTTP/1.1" 404 32498 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15"
104.161.37.234 - - [09/Oct/2026:01:02:10 +0000] "GET /manifest.json HTTP/1.1" 404 32434 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"
104.161.37.234 - - [09/Oct/2026:01:02:12 +0000] "GET /build/manifest.json HTTP/1.1" 404 32345 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Ver
...
show less
Web App Attack
Exploited Host
๐ฉ๐ช
palzer.IT
2026-10-08 10:45:29
(1 day ago)
Fail2ban automatic report for plesk-apache-badbot: 104.161.37.234 - - [08/Oct/2026:12:44:57 +0200] G ...
show more
Fail2ban automatic report for plesk-apache-badbot: 104.161.37.234 - - [08/Oct/2026:12:44:57 +0200] GET /aura-rttv1z8mbw71q4m59op6jo0s.txt [DOMAIN_REMOVED] 301 162 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +[DOMAIN_REMOVED]
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-10-08 03:30:31
(2 days ago)
Secret file probe | method: GET | path: /var/www/.env | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64 ...
show more
Secret file probe | method: GET | path: /var/www/.env | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-10-07 21:39:41
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:46:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net) ...
show more
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:45:53.565679 2026] [security2:error] [pid 6571:tid 6571] [client 104.161.37.234:3530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dmasoftlab.com"] [uri "/.git/config"] [unique_id "asahcfxdheh-gxzGgm7i7AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Yosi
2026-10-07 14:16:48
(2 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-07 12:18:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net) ...
show more
(mod_security) mod_security (id:210492) triggered by 104.161.37.234 (we.love.servers.at.ioflood.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:18:12.604003 2026] [security2:error] [pid 14288:tid 14414] [client 104.161.37.234:12411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedprojectmanager.us"] [uri "/var/www/.env"] [unique_id "asY4hMTIY_J2Q0E397V-nQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack