๐ง๐ช
madeit
2026-09-28 12:41:24
(4 days ago)
Web App Attack
๐ช๐ธ
robotstxt
2026-09-26 20:15:50
(6 days ago)
104.22.101.228 - - [26/Sep/2026:20:15:25 +0000] "GET /assets/.env HTTP/1.1" 403 31776 "-" "Mozilla/5 ...
show more
104.22.101.228 - - [26/Sep/2026:20:15:25 +0000] "GET /assets/.env HTTP/1.1" 403 31776 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "44.204.245.65" edge="104.22.101.228"
104.22.101.228 - - [26/Sep/2026:20:15:26 +0000] "GET /tools/.env HTTP/1.1" 403 31875 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "44.204.245.65" edge="104.22.101.228"
104.22.101.228 - - [26/Sep/2026:20:15:27 +0000] "GET /.aws/credentials HTTP/1.1" 403 31775 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "44.204.245.65" edge="104.22.101.228"
104.22.101.228 - - [26/Sep/2026:20:15:36 +0000] "GET /.pypirc HTTP/1.1" 403 12 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "44.204.245.65" edge="104.22.101.228"
104.22.101.228 - - [26/Sep/2026:20:15:36 +0000] "GET /.htaccess HTTP/1.1" 403 12 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "44.204.245.65" edge="104.22.101.228"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-08 02:29:03
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Grossmann-Gruppe
2026-09-04 04:07:38
(4 weeks ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-08-24 02:03:23
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 15:39:26
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 11:39:22.267320 2026] [security2:error] [pid 17358:tid 17358] [client 104.22.101.228:11938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jonesypop.com"] [uri "/.git/HEAD"] [unique_id "aoMrKvtNdQguRSiKBcRmhwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
sajmon0011
2026-08-17 11:46:46
(1 month ago)
104.22.101.228 - - [17/Aug/2026:13:46:46 +0200] "GET /.git/HEAD HTTP/2.0" 404 196 "-" "Mozilla/5.0 ( ...
show more
104.22.101.228 - - [17/Aug/2026:13:46:46 +0200] "GET /.git/HEAD HTTP/2.0" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:16:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:16:02.715431 2026] [security2:error] [pid 13565:tid 13565] [client 104.22.101.228:10549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.miroddi.com"] [uri "/.git/HEAD"] [unique_id "aoLDQmrDJusH0ZI7SYLoPAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:33:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:33:27.513995 2026] [security2:error] [pid 22166:tid 22166] [client 104.22.101.228:13713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.iyp-home.com"] [uri "/.git/config"] [unique_id "aoKrNxqMuXYkQ5fB1kEOjwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:28:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:28:33.380176 2026] [security2:error] [pid 10864:tid 10885] [client 104.22.101.228:11406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.metropaint.net"] [uri "/.git/HEAD"] [unique_id "aoKcAUJPM9tA3yduzl1uDwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-17 04:07:37
(1 month ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 01:36:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 21:35:58.022694 2026] [security2:error] [pid 11825:tid 11825] [client 104.22.101.228:13632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kairoslogammakmur.com"] [uri "/.git/HEAD"] [unique_id "aoET_nXL8a8QDR5dNpbIyQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-16 01:32:45
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 21:12:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 17:12:25.694571 2026] [security2:error] [pid 1179567:tid 1179599] [client 104.22.101.228:13567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nobletitles.org"] [uri "/.git/config"] [unique_id "an-EuTbody7XzAjpYUBVLwAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-11 21:59:34
(1 month ago)
Auto-ban: >3000 req/min op 2026-08-11
Web App Attack
SSH
Hacking