๐ง๐ช
madeit
2026-09-12 11:32:29
(7 hours ago)
Web App Attack
Anonymous
2026-08-19 09:33:48
(3 weeks ago)
(caddyscan) Scanner path probe from 104.22.101.70 (US/United States/-): 5 in the last 3600 secs; Por ...
show more
(caddyscan) Scanner path probe from 104.22.101.70 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.101.70 - - [19/Aug/2026:09:33:45 +0000] "GET /wp-admin/js/widgets HTTP/1.1"
[REDACTED] 200 2627 104.22.101.70 - - [19/Aug/2026:09:33:46 +0000] "GET /wp-admin/css HTTP/1.1"
[REDACTED] 200 2627 104.22.101.70 - - [19/Aug/2026:09:33:46 +0000] "GET /wp-admin/includes HTTP/1.1"
[REDACTED] 200 2627 104.22.101.70 - - [19/Aug/2026:09:33:46 +0000] "GET /wp-admin/classwithtostring.php HTTP/1.1"
[REDACTED] 200 2627 104.22.101.70 - - [19/Aug/2026:09:33:46 +0000] "GET /wp-admin/css/colors/modern HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-18 00:03:10
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 20:03:04.421239 2026] [security2:error] [pid 14532:tid 14532] [client 104.22.101.70:9418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thegoldentether.com"] [uri "/.git/config"] [unique_id "aoOhOOTJ2FDrbTdCZ04c-QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 10:54:49
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:54:45.575492 2026] [security2:error] [pid 17860:tid 17860] [client 104.22.101.70:11415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.visage-nico.com"] [uri "/.git/config"] [unique_id "aoLodZRr55lQrSwkcfQ17AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:59:04
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:58:58.919298 2026] [security2:error] [pid 8476:tid 8476] [client 104.22.101.70:13327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.trispeccorp.com"] [uri "/.git/config"] [unique_id "aoLbYmLR6LE8FyOWYKgugAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Oakley
2026-08-17 05:36:05
(3 weeks ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-16 21:51:26
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 17:51:19.570949 2026] [security2:error] [pid 28524:tid 28551] [client 104.22.101.70:10375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.boxvalleyrockers.com"] [uri "/.git/HEAD"] [unique_id "aoIw11vlNT12CAH8pu3zdQAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:09:54
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:09:49.259974 2026] [security2:error] [pid 29040:tid 29040] [client 104.22.101.70:12389] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.naturalacu.com"] [uri "/.git/config"] [unique_id "aoFGHZw4N_qzsKoXQn_0sQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:08:33
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:08:27.403598 2026] [security2:error] [pid 10355:tid 10355] [client 104.22.101.70:10955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.karturo.com"] [uri "/.git/config"] [unique_id "aoEpqwxH0soHr7hXWOb2ZgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-14 21:25:43
(4 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 14:31:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 10:30:59.024907 2026] [security2:error] [pid 25924:tid 25924] [client 104.22.101.70:13643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clinicacero.carpascarpe.com"] [uri "/.git/HEAD"] [unique_id "ansyI91LRnIbmAlFvF2NkQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-05 06:59:44
(1 month ago)
Web App Attack
๐ฉ๐ช
acadeova
2026-07-25 16:09:16
(1 month ago)
๐จ Recon detected (nft drop)
SRC=104.22.101.70
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=104.22.101.70
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2026-07-03 13:42:03
(2 months ago)
104.22.101.70 - - [03/Jul/2026:15:42:02 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 441 ...
show more
104.22.101.70 - - [03/Jul/2026:15:42:02 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
104.22.101.70 - - [03/Jul/2026:15:42:02 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
104.22.101.70 - - [03/Jul/2026:15:42:03 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
104.22.101.70 - - [03/Jul/2026:15:42:03 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
104.22.101.70 - - [03/Jul/2026:15:42:03 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-
...
show less
Brute-Force
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-05-14 23:43:55
(3 months ago)
2026-05-14 11:39:22 /
Web App Attack