๐ง๐ท
Peregrine
2026-07-23 03:08:52
(15 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.aws/config HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.git-credentials HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.git/config HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.gitlab-ci.yml HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.gitconfig HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
Matthew Ping
2026-07-22 17:48:19
(1 day ago)
ModSecurity rule 949110 triggered on wp2. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ง๐ท
Peregrine
2026-07-22 03:08:38
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.aws/config HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.git-credentials HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.git/config HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.gitlab-ci.yml HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.gitconfig HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 414
show less
Bad Web Bot
๐ฌ๐ง
openstrike.co.uk
2026-07-21 05:13:55
(2 days ago)
83 attacks on env grabbing URLs, PHP URLs, VC URLs, config grabbing URLs (type 2), password grabbing ...
show more
83 attacks on env grabbing URLs, PHP URLs, VC URLs, config grabbing URLs (type 2), password grabbing URLs:
GET /laravel/.env HTTP/1.1
GET /wp-config.php.old HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /auth.json HTTP/1.1
GET /.aws/credentials HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ท
Peregrine
2026-07-21 03:08:37
(2 days ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.aws/config HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.git-credentials HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.git/config HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.gitlab-ci.yml HTTP/1.1" 404 414
104.198.116.220 172.70.223.27 - - [19/Jul/2026:20:25:45 -0300] "GET /.gitconfig HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
104.198.116.220 172.70.223.28 - - [19/Jul/2026:20:25:45 -0300] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
drewking
2026-07-20 15:53:56
(3 days ago)
Rate-limit abuse โ 7 requests in a short window (brute-force / scraping). Targeted paths: /dashboard ...
show more
Rate-limit abuse โ 7 requests in a short window (brute-force / scraping). Targeted paths: /dashboard, /login, /app, /settings, /console.
show less
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
LRob
2026-07-20 13:33:41
(3 days ago)
CrowdSec: crowdsecurity/http-probing | req: /.aws/config | 11 distinct paths | UA: Mozilla/5.0 Apple ...
show more
CrowdSec: crowdsecurity/http-probing | req: /.aws/config | 11 distinct paths | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot
show less
Port Scan
Web App Attack
๐ฎ๐น
alessio loto
2026-07-20 13:00:04
(3 days ago)
WAF Detection: Security_Scanner_Blocked (High Risk IP). AI Confirmed Attack Payload.
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-07-20 12:13:48
(3 days ago)
104.198.116.220 - - [20/Jul/2026:15:13:47 +0300] "GET /.openclaw/.env HTTP/1.1" 404 650 "-" "Mozilla ...
show more
104.198.116.220 - - [20/Jul/2026:15:13:47 +0300] "GET /.openclaw/.env HTTP/1.1" 404 650 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
...
show less
Web App Attack
Anonymous
2026-07-20 12:07:53
(3 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 10:39:10
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 104.198.116.220 (220.116.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.198.116.220 (220.116.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:39:03.668405 2026] [security2:error] [pid 13259:tid 13259] [client 104.198.116.220:58754] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adultshop61.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adultshop61.net"] [uri "/server.key"] [unique_id "al36x8Kq3HKJ1BhN7ePHKwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-07-20 10:10:49
(3 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-07-20 10:06:05
(3 days ago)
Probing for exploits
104.198.116.220 - - [20/Jul/2026:12:06:02 +0200] "GET /.gitconfig HTTP/2.0" 422 ...
show more
Probing for exploits
104.198.116.220 - - [20/Jul/2026:12:06:02 +0200] "GET /.gitconfig HTTP/2.0" 422 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
104.198.116.220 - - [20/Jul/2026:12:06:02 +0200] "GET /.aws/credentials HTTP/2.0" 422 0 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 09:15:11
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 104.198.116.220 (220.116.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.198.116.220 (220.116.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 05:15:04.374952 2026] [security2:error] [pid 21379:tid 21379] [client 104.198.116.220:45336] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scatchellsbeefstand.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scatchellsbeefstand.com"] [uri "/z9x8c7v6b5-debug-trigger-scatchellsbeefstand.com"] [unique_id "al3nGFnmWBFNYkTXQe89cgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
GEDAL
2026-07-20 09:14:43
(3 days ago)
Fail2ban nginx-git @ <hostname> : 104.198.116.220 - - [20/Jul/2026:11:14:41 +0200] "GET /.git/config ...
show more
Fail2ban nginx-git @ <hostname> : 104.198.116.220 - - [20/Jul/2026:11:14:41 +0200] "GET /.git/config HTTP/2.0" 301 162 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)"
show less
Brute-Force
SSH