๐ณ๐ฑ
Alt255
2026-09-16 10:39:04
(1 week ago)
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.199.207.222 - - [16/Sep/2026:12:38:49 +0200] "GET /.git/config HTTP/1.1" 404 144108 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-16 07:03:45
(1 week ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 06:01:44
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ท
Halux
2026-09-16 05:35:14
(1 week ago)
104.199.207.222 Probing protected path or service
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-16 04:48:56
(1 week ago)
cloudlinux2 fail2ban: 2026-09-16 06:44:14,055 fail2ban.actions [1818]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-16 06:44:14,055 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Unban 107.167.184.47cloudlinux2 fail2ban: 2026-09-16 06:44:42,305 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Ban 104.199.207.222cloudlinux2 fail2ban: 2026-09-16 06:44:41,964 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 104.199.207.222 - 2026-09-16 06:44:41cloudlinux2 fail2ban: 2026-09-16 06:44:42,168 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 104.199.207.222 - 2026-09-16 06:44:42cloudlinux2 fail2ban: 2026-09-16 06:44:42,311 fail2ban.filter [1818]: INFO [recidive] Found 104.199.207.222 - 2026-09-16 06:44:42cloudlinux2 fail2ban: 2026-09-16 06:44:41,550 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 104.199.207.222 - 2026-09-16 06:44:41cloudlinux2 fail2ban: 2026-09-16 06:45:02,593 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 116.15.165.242 - 2026-09-16 06:45:01cloudlinux2 fail2ban: 2026-09-16 06:46:5
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:19:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.199.207.222 (222.207.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.207.222 (222.207.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:19:38.945567 2026] [security2:error] [pid 13964:tid 13964] [client 104.199.207.222:51142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.concertoaccordion.accordionclub.org"] [uri "/.git/config"] [unique_id "aqoKyiDRhz_Q4vaMyTn7BQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-15 22:03:55
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-15
Web App Attack
SSH
Hacking
๐ฉ๐ช
yitzhaq
2026-09-15 20:45:52
(1 week ago)
104.199.207.222 - - [15/Sep/2026:22:45:47 +0200] "GET /.env HTTP/1.1" 404 524 "-" "Mozilla/5.0 (X11; ...
show more
104.199.207.222 - - [15/Sep/2026:22:45:47 +0200] "GET /.env HTTP/1.1" 404 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.207.222 - - [15/Sep/2026:22:45:47 +0200] "GET /.env.local HTTP/1.1" 404 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.207.222 - - [15/Sep/2026:22:45:47 +0200] "GET /.env.production HTTP/1.1" 404 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.207.222 - - [15/Sep/2026:22:45:47 +0200] "GET /.env.staging HTTP/1.1" 404 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.207.222 - - [15/Sep/2026:22:45:48 +0200] "GET /.env.development HTTP/1.1" 404 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.207.222 - - [15/Sep/2026:
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 19:25:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.199.207.222 (222.207.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.207.222 (222.207.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:25:38.509618 2026] [security2:error] [pid 19677:tid 19677] [client 104.199.207.222:53918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maps.marat.info"] [uri "/.git/config"] [unique_id "aqmbsjqrBGcpxTB4BQENIAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
oja
2026-09-15 16:14:22
(1 week ago)
Aggressive web scanner
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 14:24:03
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 13:56:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.199.207.222 (222.207.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.207.222 (222.207.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:56:26.810677 2026] [security2:error] [pid 16043:tid 16043] [client 104.199.207.222:54428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dusty-buggz.aisoftwaretools.com"] [uri "/.git/config"] [unique_id "aqlOisunobcAbzdff-NGNQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-15 13:43:20
(1 week ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (63, Abuse: 56)
show less
Hacking
Exploited Host
Web App Attack
๐จ๐ญ
zynex
2026-09-15 13:19:03
(1 week ago)
URL Probing: /web/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 12:03:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.199.207.222 (222.207.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.207.222 (222.207.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:02:53.834692 2026] [security2:error] [pid 9369:tid 9369] [client 104.199.207.222:55244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.duraluxetile.ipostsocialmedia.com"] [uri "/.git/config"] [unique_id "aqkz7Q0fgIiudLYtkL7qiAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack