๐ท๐ธ
iphouse
2026-10-01 11:30:03
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-apache jail
Web App Attack
๐ฌ๐ง
sandra361
2026-09-06 11:54:32
(3 weeks ago)
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=104.2 ...
show more
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=104.22.102.80 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=62164 DF PROTO=TCP SPT=11245 DPT=443 WINDOW=65535 RES=0x00 ACK RST URGP=0
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-09-04 22:01:31
(4 weeks ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
๐ง๐ช
madeit
2026-09-04 19:08:27
(4 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 12:55:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:55:22.704757 2026] [security2:error] [pid 13509:tid 13509] [client 104.22.102.80:13375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tribalpacifica.com"] [uri "/.git/HEAD"] [unique_id "aoMEuqTSviIA0ZFNEnth1QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:56:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:56:26.395228 2026] [security2:error] [pid 16550:tid 16550] [client 104.22.102.80:12678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sharonmauldin.com"] [uri "/.git/config"] [unique_id "aoLMukgqPdAHG2AwcXBIhQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:02:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:02:42.501458 2026] [security2:error] [pid 5902:tid 5994] [client 104.22.102.80:10025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ardentsi.com"] [uri "/.git/HEAD"] [unique_id "aoKyEr1dsjzss_eEX47j6wAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 04:45:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:45:29.767291 2026] [security2:error] [pid 16987:tid 16987] [client 104.22.102.80:10479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.anneoday.com"] [uri "/.git/HEAD"] [unique_id "aoKR6TYW7M7ytpHmoDhbvAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 10:15:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:14:59.150941 2026] [security2:error] [pid 8524:tid 8524] [client 104.22.102.80:12006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rahmanou.com"] [uri "/.git/HEAD"] [unique_id "aoGNo53kx3FhGUxkn2nxfQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:49:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:49:41.949377 2026] [security2:error] [pid 24731:tid 24731] [client 104.22.102.80:13998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dcmillerjr.com"] [uri "/.git/HEAD"] [unique_id "aoFPdVmi3a0bf0XqTBtTkQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-14 01:25:02
(1 month ago)
suspicious request in access.log
Web App Attack
๐ง๐ช
madeit
2026-08-13 08:07:21
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 07:54:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 03:54:22.023085 2026] [security2:error] [pid 1285957:tid 1285957] [client 104.22.102.80:13205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjtent.com"] [uri "/.git/HEAD"] [unique_id "an14LsDMW9X0bK44TT--swAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 03:12:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.102.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 23:12:16.702026 2026] [security2:error] [pid 6968:tid 6968] [client 104.22.102.80:10955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.raynernet.com"] [uri "/.git/HEAD"] [unique_id "anqTEFFlkvqmw_wNaZ-vVgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 05:42:55
(2 months ago)
104.22.102.80 - - [29/Jul/2026:07:42:54 +0200] "GET /wordpress/.env HTTP/1.1" 403 1738 "-" "Mozilla/ ...
show more
104.22.102.80 - - [29/Jul/2026:07:42:54 +0200] "GET /wordpress/.env HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.102.80 - - [29/Jul/2026:07:42:54 +0200] "GET /wordpress/.env HTTP/1.1" 403 737 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.102.80 - - [29/Jul/2026:07:42:54 +0200] "GET /wp/.env HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.102.80 - - [29/Jul/2026:07:42:54 +0200] "GET /wp/.env HTTP/1.1" 403 737 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.102.80 - - [29/Jul/2026:07:42:54 +0200] "GET /cms/.env HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.3
...
show less
Bad Web Bot
Web App Attack