๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(13 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Philister11
2026-09-23 00:45:17
(18 hours ago)
CrowdSec: crowdsecurity/http-crawl-non_statics (BE/AS396982)
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-22 22:14:50
(21 hours ago)
Brute-Force
Web App Attack
Anonymous
2026-09-22 21:57:10
(21 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 104.199.72.70 (70.72.199.104.bc.googleuserco ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 104.199.72.70 (70.72.199.104.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.199.72.70 - - [22/Sep/2026:23:57:08 +0200] "GET /.//.env HTTP/2.0" 406 317 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
104.199.72.70 - - [22/Sep/2026:23:57:08 +0200] "GET /..%2f.env HTTP/2.0" 406 317 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
104.199.72.70 - - [22/Sep/2026:23:57:08 +0200] "GET //.env HTTP/2.0" 406 317 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
show less
Port Scan
๐ฉ๐ช
updown.io
2026-09-22 20:32:47
(22 hours ago)
{"level":"info","ts":1790109164.9609377,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790109164.9609377,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"104.199.72.70","remote_port":"40882","client_ip":"104.199.72.70","proto":"HTTP/2.0","method":"GET","host":"status.checkip.info","uri":"/manifest.json","headers":{"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Sec-Fetch-Dest":["document"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Sec-Fetch-Site":["none"],"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-User":["?1"],"Priority":["u=0, i"],"Upgrade-Insecure-Requests":["1"],"Se
...
show less
DDoS Attack
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-22 18:08:14
(1 day ago)
[Wed Sep 23 04:08:14.244234 2026] [security2:error] [pid 277068] [client 104.199.72.70:35668] [clien ...
show more
[Wed Sep 23 04:08:14.244234 2026] [security2:error] [pid 277068] [client 104.199.72.70:35668] [client 104.199.72.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "underconstruction.paulshipley.info"] [uri "/"] [unique_id "arLEDuNYFVbgdXeycAjCBgAAAAA"]
...
show less
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-22 16:55:43
(1 day ago)
104.199.72.70 - - [22/Sep/2026:17:55:41 +0100] "GET /roundcube/webpack-stats.json HTTP/2.0" 404 994 ...
show more
104.199.72.70 - - [22/Sep/2026:17:55:41 +0100] "GET /roundcube/webpack-stats.json HTTP/2.0" 404 994 "https://webmail.betatechnologies.info/webpack-stats.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
show less
Bad Web Bot
Anonymous
2026-09-22 16:47:56
(1 day ago)
104.199.72.70 detected on srv01
Brute-Force
๐บ๐ธ
n2nguyenn2nguyen
2026-09-22 16:43:29
(1 day ago)
Blocked by YFC Security on https://1904.brixzly.com โ type: directory_scan_attempts
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:34:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.72.70 (70.72.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.72.70 (70.72.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:34:50.118132 2026] [security2:error] [pid 4154:tid 4154] [client 104.199.72.70:54156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tavo.info"] [uri "/.env.development"] [unique_id "arKSCoDvDqBW-PBKmb4wqAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:13:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.199.72.70 (70.72.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.72.70 (70.72.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:13:25.600782 2026] [security2:error] [pid 19396:tid 19396] [client 104.199.72.70:47554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.solarfarms.info|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.solarfarms.info"] [uri "/rclone.conf"] [unique_id "arKNBQ1FHmyjNFAIuYkEOAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Nevermind
2026-09-22 13:27:01
(1 day ago)
104.199.72.70 - - [22/Sep/2026:15:27:01 +0200] "GET /.env HTTP/1.1" 403 6270 "-" "Mozilla/5.0 AppleW ...
show more
104.199.72.70 - - [22/Sep/2026:15:27:01 +0200] "GET /.env HTTP/1.1" 403 6270 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
104.199.72.70 - - [22/Sep/2026:15:27:01 +0200] "GET /.env.production HTTP/1.1" 403 6270 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
104.199.72.70 - - [22/Sep/2026:15:27:01 +0200] "GET /.env.example HTTP/1.1" 403 6270 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
104.199.72.70 - - [22/Sep/2026:15:27:01 +0200] "GET /.env.local HTTP/1.1" 403 6270 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:26:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.72.70 (70.72.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.72.70 (70.72.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:26:44.571375 2026] [security2:error] [pid 3097:tid 3097] [client 104.199.72.70:34798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.keystroke.info"] [uri "/.env"] [unique_id "arKCFGt5EFqSKpe0I9IYhAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-22 13:03:08
(1 day ago)
2026/09/22 14:03:06 [error] 325888#325888: *1311237 limiting requests, excess: 200.190 by zone "floo ...
show more
2026/09/22 14:03:06 [error] 325888#325888: *1311237 limiting requests, excess: 200.190 by zone "flood", client: 104.199.72.70, server: [redacted], request: "GET /static//app/.env HTTP/2.0", host: "www.betatechnologies.info"
2026/09/22 14:03:06 [error] 325888#325888: *1311237 limiting requests, excess: 200.170 by zone "flood", client: 104.199.72.70, server: [redacted], request: "GET /static//.env HTTP/2.0", host: "www.betatechnologies.info"
2026/09/22 14:03:06 [error] 325888#325888: *1311237 limiting requests, excess: 200.510 by zone "flood", client: 104.199.72.70, server: [redacted], request: "GET /.//.env HTTP/2.0", host: "www.betatechnologies.info"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 12:57:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.72.70 (70.72.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.72.70 (70.72.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:57:39.896500 2026] [security2:error] [pid 28661:tid 28661] [client 104.199.72.70:40280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.afjm.info"] [uri "/dist../.env"] [unique_id "arJ7Q4jClcTv6Cy7FuOTwAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack