๐ซ๐ท
guillaume illien
2026-07-27 10:58:04
(10 hours ago)
104.199.215.82 - - [27/Jul/2026:10:58:02 +0000] "GET /assets/manifest.json HTTP/1.1" 404 197 "-" "Mo ...
show more
104.199.215.82 - - [27/Jul/2026:10:58:02 +0000] "GET /assets/manifest.json HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
104.199.215.82 - - [27/Jul/2026:10:58:04 +0000] "GET /assets/worders_users/controllers/new_service_customer_preferred_linguists_controller-3745ba9d0bc9b553bfc6b18ef5da8ce62ea68825d8225214bff5372507fcd94f.js.map HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
104.199.215.82 - - [27/Jul/2026:10:58:04 +0000] "GET /assets/active_admin/json_editor-77c2af8dd6c3b7dc73ede9a33f122fe4099650c78db18d42e4a2b50334220553.js.map HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
104.199.215.82 - - [27/Jul/2026:10:58:04 +0000] "GET /assets/worders_core/controllers/session_new_controller-bf394b75732ceffdd392dc713e6ef4135d1d9ed
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ช๐ธ
librebit
2026-07-27 09:32:15
(12 hours ago)
Brute force
Brute-Force
๐ณ๐ฑ
Site.eu
2026-07-27 09:20:24
(12 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
Bedios GmbH
2026-07-27 09:20:21
(12 hours ago)
Login credentials theft attempt
Hacking
๐ฎ๐ฉ
David Koswari
2026-07-27 05:33:00
(16 hours ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ฎ๐น
CoreTech srl
2026-07-27 04:38:17
(17 hours ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
Anonymous
2026-07-27 03:07:35
(18 hours ago)
Aggressive web scan
Web App Attack
๐ญ๐บ
DumaNet
2026-07-27 02:47:00
(19 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jul 26. 16:58:51
Source IP: 104.19 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jul 26. 16:58:51
Source IP: 104.199.215.82
Portion of the log(s):
104.199.215.82 - [26/Jul/2026:16:58:51 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
104.199.215.82 - [26/Jul/2026:16:58:51 +0200] "GET /.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
104.199.215.82 - [26/Jul/2026:16:58:51 +0200] "GET /.git-credentials HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
104.199.215.82 - [26/Jul/2026:16:58:51 +0200] "GET /.gitlab-ci.yml HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
104.199.215.82 - [26/Jul/2026:16:58:51 +0200] "GET /.aws/config HTTP/1.1" 404 153 "-" "Mozilla/5.0
show less
Web App Attack
๐ฉ๐ช
macrob
2026-07-27 01:33:26
(20 hours ago)
2026/07/27 01:33:25 [error] 3625869#3625869: *415227233 access forbidden by rule, client: 104.199.21 ...
show more
2026/07/27 01:33:25 [error] 3625869#3625869: *415227233 access forbidden by rule, client: 104.199.215.82, server: fn.binixo.es, request: "GET /.vscode/launch.json HTTP/2.0", host: "grafana.fastcredit.net.ua"
2026/07/27 01:33:25 [error] 3625869#3625869: *415227234 access forbidden by rule, client: 104.199.215.82, server: fn.binixo.es, request: "GET /.ssh/id_rsa HTTP/2.0", host: "grafana.fastcredit.net.ua"
2026/07/27 01:33:25 [error] 3625869#3625869: *415227238 access forbidden by rule, client: 104.199.215.82, server: fn.binixo.es, request: "GET /.ssh/config HTTP/2.0", host: "grafana.fastcredit.net.ua"
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-07-27 00:45:04
(21 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-27 00:00:59
(21 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
cloudmax
2026-07-26 23:25:29
(22 hours ago)
Cloudmax Protect [WEB BLOCK] - Too many 400/500 requests. Possible attack or hacking attempt
Hacking
Web App Attack
๐ฉ๐ช
macrob
2026-07-26 22:17:02
(23 hours ago)
2026/07/26 22:16:59 [error] 3625868#3625868: *414817390 access forbidden by rule, client: 104.199.21 ...
show more
2026/07/26 22:16:59 [error] 3625868#3625868: *414817390 access forbidden by rule, client: 104.199.215.82, server: fn.binixo.es, request: "GET /.git/HEAD HTTP/2.0", host: "crm.fastcredit.net.ua"
2026/07/26 22:16:59 [error] 3625868#3625868: *414817394 access forbidden by rule, client: 104.199.215.82, server: fn.binixo.es, request: "GET /.gitconfig HTTP/2.0", host: "crm.fastcredit.net.ua"
2026/07/26 22:16:59 [error] 3625866#3625866: *414817392 access forbidden by rule, client: 104.199.215.82, server: fn.binixo.es, request: "GET /.aws/credentials HTTP/2.0", host: "crm.fastcredit.net.ua"
...
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-07-26 22:14:23
(23 hours ago)
[Mon Jul 27 00:14:22.751406 2026] [proxy_fcgi:error] [pid 1297036:tid 1298629] [remote 104.199.215.8 ...
show more
[Mon Jul 27 00:14:22.751406 2026] [proxy_fcgi:error] [pid 1297036:tid 1298629] [remote 104.199.215.82:0] AH01071: Got error 'Primary script unknown\n'
[Mon Jul 27 00:14:22.751420 2026] [proxy_fcgi:error] [pid 1297036:tid 1299475] [remote 104.199.215.82:0] AH01071: Got error 'Primary script unknown\n'
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Eric
2026-07-26 22:06:35
(23 hours ago)
[Sun Jul 26 22:06:34.697256 2026] [security2:error] [pid 2579375:tid 2579375] [client 104.199.215.82 ...
show more
[Sun Jul 26 22:06:34.697256 2026] [security2:error] [pid 2579375:tid 2579375] [client 104.199.215.82:0] [client 104.199.215.82] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/.gitlab-ci.yml"] [unique_id "amaE6qmU93hfUc0_9B32swAAAD4"]
[Sun Jul 26 22:06:34.869443 2026] [security2:error] [pid 2579370:tid 2579370] [client 104.199.215.82:0] [client 104.199.215.82] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
Hacking
Web App Attack