๐บ๐ธ
solantex
2026-09-29 19:02:42
(1 day ago)
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or tes ...
show more
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or test permission has been granted to this source.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:21:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.197.170.92 (92.170.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.170.92 (92.170.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:21:40.167478 2026] [security2:error] [pid 18955:tid 18955] [client 104.197.170.92:53016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thefrontporchoffering.com"] [uri "/.git/config"] [unique_id "arsElKmfEM3xcNfmisSgSQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 14:31:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.197.170.92 (92.170.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.170.92 (92.170.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 10:30:58.185531 2026] [security2:error] [pid 2924:tid 2924] [client 104.197.170.92:52452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frickandfracks.com"] [uri "/.git/config"] [unique_id "arp6Ijb6-I6EpVCim5C92QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-28 04:27:19
(2 days ago)
104.197.170.92 - - [28/Sep/2026:04:27:00 +0000] "GET /turismo/banos-de-urquizar/.env HTTP/1.1" 403 1 ...
show more
104.197.170.92 - - [28/Sep/2026:04:27:00 +0000] "GET /turismo/banos-de-urquizar/.env HTTP/1.1" 403 12468 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.197.170.92"
104.197.170.92 - - [28/Sep/2026:04:27:01 +0000] "GET /turismo/banos-de-urquizar/.env.local HTTP/1.1" 403 12468 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.197.170.92"
104.197.170.92 - - [28/Sep/2026:04:27:02 +0000] "GET /turismo/banos-de-urquizar/.env.production HTTP/1.1" 403 12538 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.197.170.92"
104.197.170.92 - - [28/Sep/2026:04:27:02 +0000] "GET /turismo/banos-de-urquizar/.env.staging HTTP/1.1" 403 12468 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.197.170.92"
104.197.170.92 - -
...
show less
Web App Attack
๐ฉ๐ช
rh24
2026-09-27 01:35:56
(3 days ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 104.197.170.92 (US/United States/92.170.1 ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 104.197.170.92 (US/United States/92.170.197.104.bc.googleusercontent.com)
show less
Hacking
๐ฆ๐บ
electronico
2026-09-26 22:12:52
(3 days ago)
104.197.170.92 - - [27/Sep/2026:09:12:49 +1100] "GET /.env.local HTTP/1.1" 404 2104 "-" "Mozilla/5.0 ...
show more
104.197.170.92 - - [27/Sep/2026:09:12:49 +1100] "GET /.env.local HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.197.170.92 - - [27/Sep/2026:09:12:49 +1100] "GET /.env.production HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.197.170.92 - - [27/Sep/2026:09:12:50 +1100] "GET /.env.staging HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.197.170.92 - - [27/Sep/2026:09:12:50 +1100] "GET /.env.development HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.197.170.92 - - [27/Sep/2026:09:12:50 +1100] "GET /.env.test HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.197.170.92 - - [27/Sep/2
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-26 21:59:56
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-25.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-26 10:26:19
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-26 10:03:19
(4 days ago)
20 attempts against mh_ha-misbehave-ban on pf221113
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-26 09:21:18
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
debestelapp
2026-09-26 07:55:09
(4 days ago)
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-26 07:40:44
(4 days ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 21:53:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.197.170.92 (92.170.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.170.92 (92.170.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 17:53:11.764728 2026] [security2:error] [pid 7775:tid 7896] [client 104.197.170.92:50626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.undergroundinternational.com"] [uri "/.git/config"] [unique_id "arbtR_akw1jo2ov68Xg8RgAAAkU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-25 21:12:04
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
kosada.com
2026-09-24 19:05:52
(6 days ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack