๐ง๐ช
madeit
2026-10-05 15:07:59
(18 hours ago)
Web App Attack
๐ง๐ช
madeit
2026-09-22 21:41:42
(1 week ago)
Web App Attack
๐ฑ๐บ
conseilgouz
2026-09-05 22:59:23
(1 month ago)
are-17 : Block hidden directories=>/.env.production(/)
Hacking
๐ง๐ฌ
Stoyko Stoykov
2026-08-28 23:18:45
(1 month ago)
104.22.105.2 - - [29/Aug/2026:02:18:44 +0300] "HEAD /.env.production.local HTTP/2.0" 404 0 "https:// ...
show more
104.22.105.2 - - [29/Aug/2026:02:18:44 +0300] "HEAD /.env.production.local HTTP/2.0" 404 0 "https://www.google.com/search?q=bitwarden.it-systems.org" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Hacking
Web App Attack
๐ง๐ช
madeit
2026-08-28 20:12:51
(1 month ago)
Web App Attack
๐บ๐ธ
threatintelligence_bvc
2026-08-23 12:06:40
(1 month ago)
Brute-Force
๐ง๐ช
madeit
2026-08-20 22:01:39
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:25:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:25:44.653424 2026] [security2:error] [pid 6841:tid 6841] [client 104.22.105.2:11999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.c2cdisasterresponse.org"] [uri "/.git/HEAD"] [unique_id "aoFl-PK6gLChkxwPp9aUHgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 04:59:37
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:59:34.627747 2026] [security2:error] [pid 7749:tid 7749] [client 104.22.105.2:11052] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "desertviewgroupllc.com"] [uri "/.git/HEAD"] [unique_id "aoFDtltGBWnmi3ieJsIb8gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:09:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:09:33.975404 2026] [security2:error] [pid 3393625:tid 3393695] [client 104.22.105.2:11260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eafm.org"] [uri "/.git/HEAD"] [unique_id "aoEp7flZz09EeVygTLakHAAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-06 03:46:34
(2 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:24:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:24:03.738377 2026] [security2:error] [pid 14434:tid 14434] [client 104.22.105.2:10924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valueandmeaning.com"] [uri "/.env.bak"] [unique_id "agbmM2FU78RswgI517iCSQAAACI"], referer: https://www.google.com/search?q=valueandmeaning.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:28:35
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.22.105.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:27:45.197827 2026] [security2:error] [pid 12533:tid 12533] [client 104.22.105.2:11586] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||taekwondoit.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "taekwondoit.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aga84U-Xnwlzs7YfoFaX0gAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 05:02:25
(4 months ago)
(caddyscan) Scanner path probe from 104.22.105.2 (US/United States/-): 5 in the last 3600 secs; Port ...
show more
(caddyscan) Scanner path probe from 104.22.105.2 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:04:07:05 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:04:33:30 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:05:01:14 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:05:01:18 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:05:01:40 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-14 01:27:51
(4 months ago)
(caddyscan) Scanner path probe from 104.22.105.2 (US/United States/-): 5 in the last 3600 secs; Port ...
show more
(caddyscan) Scanner path probe from 104.22.105.2 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:00:30:46 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:00:42:42 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:00:50:34 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:01:11:15 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.105.2 - - [14/May/2026:01:27:47 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan