๐ง๐ช
madeit
2026-09-20 12:26:36
(3 days ago)
Web App Attack
๐บ๐ธ
johnkarlhill
2026-09-14 09:22:43
(1 week ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-17 07:33:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:33:19.772521 2026] [security2:error] [pid 1758:tid 1802] [client 104.22.104.218:11014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cmykdesign.com"] [uri "/.git/HEAD"] [unique_id "aoK5P8bHfhT1DYlLVDvKmgAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:42:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:42:22.002600 2026] [security2:error] [pid 6057:tid 6057] [client 104.22.104.218:9409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jeffhenry.net"] [uri "/.git/HEAD"] [unique_id "aoKfPiWm4JibbLBtTC5BIwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-16 22:02:25
(1 month ago)
Auto-ban: >3000 req/min op 2026-08-16
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-16 07:37:26
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:37:21.394039 2026] [security2:error] [pid 8759:tid 8759] [client 104.22.104.218:10544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itsupitsdown.com"] [uri "/.git/HEAD"] [unique_id "aoFosZDpM20x9Odo7n-K0QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 04:14:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:14:31.183226 2026] [security2:error] [pid 11124:tid 11124] [client 104.22.104.218:9968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.visco174.com"] [uri "/.git/config"] [unique_id "aoE5JxRw1J1EG99Q7v5ssAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:53:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:53:00.107594 2026] [security2:error] [pid 22936:tid 22936] [client 104.22.104.218:9439] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.speedysremodeling.com"] [uri "/.git/HEAD"] [unique_id "aoE0HLUh3DIRwvnUVTA86wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-10 06:24:15
(1 month ago)
Web App Attack
๐บ๐ธ
mawan
2026-07-06 05:36:31
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
CrystalMaker
2026-07-02 01:31:04
(2 months ago)
Vulnerability scan - GET /__web_secure_probe_1782955857437461461_20 HTTP/2.0
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-15 08:48:58
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:48:46.055943 2026] [security2:error] [pid 17613:tid 17633] [client 104.22.104.218:11337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aliqshacommoditiescorporation.com.aliqsha.com"] [uri "/.env.backup"] [unique_id "agbd7ketDh-9cHsK9zGcNwAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 05:01:36
(4 months ago)
(caddyscan) Scanner path probe from 104.22.104.218 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 104.22.104.218 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:04:30:41 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:04:31:33 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:04:58:39 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:05:01:15 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:05:01:18 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-14 03:26:28
(4 months ago)
(caddyscan) Scanner path probe from 104.22.104.218 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 104.22.104.218 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:02:31:49 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:03:00:35 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:03:11:55 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:03:12:29 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.218 - - [14/May/2026:03:26:26 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
pltcldvlpr
2026-05-14 02:32:21
(4 months ago)
CMS/framework probe. Matched path: 104.22.104.218 - - [14/May/2026:04:32:21 +0200] "GET /.env.local ...
show more
CMS/framework probe. Matched path: 104.22.104.218 - - [14/May/2026:04:32:21 +0200] "GET /.env.local HTTP/2.0" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" asn=13335 org="Cloudflare, Inc.": 104.22.104.218 - - [14/May/2026:04:32:21 +0200] "GET /.env.local HTTP/2.0" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" asn=13335 org="Cloudflare, Inc."
...
show less
Web App Attack