๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(2 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฎ๐น
CoreTech srl
2026-09-16 11:03:59
(21 hours ago)
cloudlinux2 fail2ban: 2026-09-16 12:59:16,054 fail2ban.actions [1818]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-16 12:59:16,054 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Unban 106.51.105.77cloudlinux2 fail2ban: 2026-09-16 12:59:35,291 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Unban 165.51.36.17cloudlinux2 fail2ban: 2026-09-16 12:59:31,464 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 136.144.42.60 - 2026-09-16 12:59:31cloudlinux2 fail2ban: 2026-09-16 13:00:35,665 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 158.46.161.79 - 2026-09-16 13:00:35cloudlinux2 fail2ban: 2026-09-16 13:02:47,233 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 104.199.242.12 - 2026-09-16 13:02:47cloudlinux2 fail2ban: 2026-09-16 13:02:47,449 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 104.199.242.12 - 2026-09-16 13:02:47cloudlinux2 fail2ban: 2026-09-16 13:02:47,021 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 104.199.242.12 - 2026-09-16 13:02:47cloudlinux2 fail2ban: 2026-09-16 13:02:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:24:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:24:20.871530 2026] [security2:error] [pid 26592:tid 26592] [client 104.199.242.12:58290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kennethandsharon.stardancertantra.com"] [uri "/.git/config"] [unique_id "aqpEJLuHoafgiSzW6EHu5gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-16 06:52:44
(1 day ago)
Suspicious URL access.
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-16 05:19:45
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /current/.env | Evidence: avesviagens.pt 104.199. ...
show more
Web scanning / probing for vulnerable paths | URL: /current/.env | Evidence: avesviagens.pt 104.199.242.12 - - [16/Sep/2026:07:19:21 +0200] \"GET /current/.env HTTP/1.1\" 404 22694 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=TW | ASN: GOOGLE-CLOUD-PLATFORM | Country: TW
show less
Port Scan
Web App Attack
๐ง๐ช
madeit
2026-09-16 04:04:42
(1 day ago)
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 02:17:50
(1 day ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:51:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:51:00.973442 2026] [security2:error] [pid 9430:tid 9430] [client 104.199.242.12:49930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kelleysbridge.com.greighhouse.com"] [uri "/.git/config"] [unique_id "aqnL1PXwn5YVQRcpCH7FtAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:22:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:22:33.563870 2026] [security2:error] [pid 12815:tid 12817] [client 104.199.242.12:42734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kellenlee.mailme.name"] [uri "/.git/config"] [unique_id "aqnFKfH9FdSgKFFmiWOBewAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-15 22:01:00
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-15
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 20:19:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:19:50.605620 2026] [security2:error] [pid 10111:tid 10193] [client 104.199.242.12:47722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.keithfamily.missmadlove.com"] [uri "/.git/config"] [unique_id "aqmoZh198T2Wrg6UoVZzLAAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-15 20:09:07
(1 day ago)
104.199.242.12 - - [15/Sep/2026:20:08:22 +0000] "POST / HTTP/1.1" 403 26465 "-" "Mozilla/5.0 (X11; L ...
show more
104.199.242.12 - - [15/Sep/2026:20:08:22 +0000] "POST / HTTP/1.1" 403 26465 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.199.242.12"
104.199.242.12 - - [15/Sep/2026:20:08:22 +0000] "POST / HTTP/1.1" 403 26465 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.199.242.12"
104.199.242.12 - - [15/Sep/2026:20:08:23 +0000] "GET /.git/config HTTP/1.1" 403 29609 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.199.242.12"
104.199.242.12 - - [15/Sep/2026:20:08:23 +0000] "GET /.env HTTP/1.1" 403 29590 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.199.242.12"
104.199.242.12 - - [15/Sep/2026:20:08:24 +0000] "GET /.env.local HTTP/1.1" 403 29609 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML
...
show less
Web App Attack
Anonymous
2026-09-15 19:18:33
(1 day ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.monastiria.gr; logs=/var/log/httpd/domains/monastiria.gr ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.monastiria.gr; logs=/var/log/httpd/domains/monastiria.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-15 19:16:26
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:03:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.242.12 (12.242.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:03:30.866595 2026] [security2:error] [pid 10064:tid 10092] [client 104.199.242.12:48754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.keetons.net.jameskeeton.com"] [uri "/.git/config"] [unique_id "aqmIct5AS0vLWKShG0WpqAAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack