π§π·
Peregrine
2026-07-21 12:19:26
(15 hours ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 104.207.60.233 172.71.120.145 - - [21/Jul/2026:09:1 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 104.207.60.233 172.71.120.145 - - [21/Jul/2026:09:19:24 -0300] "GET /wp-login.php HTTP/1.1" 404 18193
show less
Bad Web Bot
π©πͺ
iNetWorker
2026-07-05 17:59:00
(2 weeks ago)
trolling for resource vulnerabilities
Web App Attack
πΊπΈ
agenciahypelab.com.br
2026-06-16 07:23:40
(1 month ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
π¨π
TheCoon
2026-02-16 15:30:01
(5 months ago)
Automated: Credential theft attempt - JSON bomb served
Hacking
Web App Attack
π³π±
jjnxpct
2026-02-16 04:54:36
(5 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /backend/.env (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .env found within REQUEST_FILENAME: /backend/.env]
show less
Hacking
Web App Attack
Anonymous
2026-02-15 07:05:10
(5 months ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 06:39:58
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:39:54.293976 2026] [security2:error] [pid 22106:tid 22177] [client 104.207.60.233:21991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oplconnect.com"] [uri "/frontend/.env"] [unique_id "aZFqOshSZQInS4HdHIcSEAAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-02-15 05:33:32
(5 months ago)
Blocking for trying to access an exploit file: /.env.save
Hacking
π©πͺ
BlueWire Hosting
2026-02-15 05:09:18
(5 months ago)
Probing websites for vulnerabilities
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 04:45:15
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:45:01.257300 2026] [security2:error] [pid 10897:tid 10897] [client 104.207.60.233:25171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "santaclausphonecall.com"] [uri "/api/.git/config"] [unique_id "aZFPTRAgJBzkY0uHnasl7gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 04:15:59
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:15:51.694571 2026] [security2:error] [pid 16514:tid 16514] [client 104.207.60.233:39573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pozzolan.org"] [uri "/app/.git/config"] [unique_id "aZFId50odAsxZWM511PMzAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 03:57:04
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:56:59.909778 2026] [security2:error] [pid 2595:tid 2595] [client 104.207.60.233:11113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notarialota.cl"] [uri "/frontend/.env"] [unique_id "aZFECx3nczVOpFQ6L-EvkQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 02:50:58
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:50:55.046368 2026] [security2:error] [pid 234461:tid 234461] [client 104.207.60.233:13993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rwcartoons.com"] [uri "/.env"] [unique_id "aZE0j6XN3Qh1qp_S0BGf5AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 02:32:42
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.60.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:32:39.263715 2026] [security2:error] [pid 28748:tid 28748] [client 104.207.60.233:25023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rums-of-the-world.com"] [uri "/app/.git/config"] [unique_id "aZEwR6ErsRlb0SfrioC2swAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 02:16:21
(5 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.207.60.233 (CA/Canada/-)
SQL Injection