๐ง๐พ
lns.bz
2026-08-24 19:07:01
(4 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ง๐พ
lns.bz
2026-08-23 16:24:04
(1 day ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-08-23 09:52:41
(1 day ago)
(caddyscan) Scanner path probe from 104.22.100.155 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 104.22.100.155 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.100.155 - - [23/Aug/2026:09:52:21 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 2627 104.22.100.155 - - [23/Aug/2026:09:52:29 +0000] "GET /.env.save HTTP/1.1"
[REDACTED] 200 2627 104.22.100.155 - - [23/Aug/2026:09:52:29 +0000] "GET /.env.sample HTTP/1.1"
[REDACTED] 200 2627 104.22.100.155 - - [23/Aug/2026:09:52:29 +0000] "GET /.env.production.local HTTP/1.1"
[REDACTED] 200 2627 104.22.100.155 - - [23/Aug/2026:09:52:36 +0000] "GET /.vscode/settings.json HTTP/1.1"
show less
Port Scan
๐ง๐พ
lns.bz
2026-08-22 15:21:05
(2 days ago)
Too many 404 requests [BY]
Web App Attack
๐ช๐ธ
el-brujo
2026-08-20 21:33:49
(4 days ago)
20/Aug/2026:23:33:48.799876 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
20/Aug/2026:23:33:48.799876 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.22.100.155] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at ARGS_NAMES:php echo esc_url( get_option( 'home' ) ); ?>/. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: php found within ARGS_NAMES:php echo esc
...
show less
Hacking
Web App Attack
๐ง๐พ
lns.bz
2026-08-18 07:51:56
(6 days ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 02:25:43
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 22:25:40.503454 2026] [security2:error] [pid 5451:tid 5451] [client 104.22.100.155:14007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.solutionsint.com.crestrong.com"] [uri "/.git/HEAD"] [unique_id "aoPCpFDFZkiuOw2rYFM-KAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 01:42:26
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:42:18.837343 2026] [security2:error] [pid 28922:tid 28922] [client 104.22.100.155:13682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.smoothiessoupssalads.com"] [uri "/.git/config"] [unique_id "aoO4euEBFPGWi-caZlLfYgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 11:14:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:13:56.448124 2026] [security2:error] [pid 30762:tid 30762] [client 104.22.100.155:11083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "enlightened-workplace.com"] [uri "/.git/config"] [unique_id "aoLs9FgxHa-PgfAFcObzIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 10:56:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:56:18.079986 2026] [security2:error] [pid 22198:tid 22198] [client 104.22.100.155:12095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calvet1937.marcelacalvet.com"] [uri "/.git/config"] [unique_id "aoLo0l2jJBr7c71Hqc7GlwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:53:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:53:03.163348 2026] [security2:error] [pid 13035:tid 13035] [client 104.22.100.155:10332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.faeriefeelers.com"] [uri "/.git/HEAD"] [unique_id "aoKvzzyFspQax9LAuKlBTAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:12:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:11:59.617935 2026] [security2:error] [pid 29668:tid 29701] [client 104.22.100.155:13821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.esgcommission.aafm.us"] [uri "/.git/HEAD"] [unique_id "aoKmLw_BaMAqkf6y1gO-2QAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-08-16 14:00:13
(1 week ago)
16/Aug/2026:16:00:12.806420 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
16/Aug/2026:16:00:12.806420 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.22.100.155] ModSecurity: Warning. Pattern match "(?:<\\\\\\\\?(?:[^x]|x[^m]|xm[^l]|xml[^\\\\\\\\s]|xml$|$)|<\\\\\\\\?php|\\\\\\\\[(?:\\\\\\\\/|\\\\\\\\\\\\\\\\)?php\\\\\\\\])" at ARGS:_wpnonce. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "66"] [id "933100"] [msg "PHP Injection Attack: PHP Open Tag Found"] [data "Matched Data: <?p found within ARGS:_wpnonce: <?php echo urlencode( $nonce ); ?>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "el-hacker.org"] [uri "/Cursos/CEHv13/CEHv13 Lab Prerequisites/Websites/CEH WordPress Website/wp-admin/widgets.php"] [unique_id "aoHCbLsSwFKyXu25lktZQQAMgzM"]
...
show less
Hacking
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-08-16 07:50:16
(1 week ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:10:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:09:52.279562 2026] [security2:error] [pid 30978:tid 30992] [client 104.22.100.155:11970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ecothermtech.com"] [uri "/.git/HEAD"] [unique_id "aoFiQCaG0mm0q8dHph11DgAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack