π§πΎ
lns.bz
2026-10-03 20:37:40
(7 hours ago)
.env scanning [BY]
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 06:25:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.22.109.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.109.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 02:24:56.150122 2026] [security2:error] [pid 3541:tid 3541] [client 104.22.109.81:11475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigkevsperformance.com"] [uri "/.git/config"] [unique_id "ar9OOKkYvtp7LOaUTeIxqQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 15:29:53
(2 days ago)
104.22.109.81 - - [01/Oct/2026:15:29:52 +0000] "GET /wp-admin/install.php?step=1 HTTP/2.0" 404 929 " ...
show more
104.22.109.81 - - [01/Oct/2026:15:29:52 +0000] "GET /wp-admin/install.php?step=1 HTTP/2.0" 404 929 "-" "http://ashleybutcher.eu/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-10-01 04:07:07
(2 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 02:10:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.109.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.109.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:10:53.976044 2026] [security2:error] [pid 29658:tid 29658] [client 104.22.109.81:10818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "volteracommerce.com"] [uri "/.git/config"] [unique_id "ar3BLa3CXNCemuqjsIq8jwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 00:50:35
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΊπΈ
craudiovizai
2026-09-30 12:30:54
(3 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-29 23:00:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.109.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.109.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:00:52.544530 2026] [security2:error] [pid 6109:tid 6109] [client 104.22.109.81:13425] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alccontractorsllc.com"] [uri "/.git/config"] [unique_id "arxDJC3ZVUJSB-84AHjbGQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-29 14:04:00
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π³π±
Alt255
2026-09-29 00:00:13
(5 days ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.22.109.81 - - [29/Sep/2026:01:59:51 +0200] "GET /.git/config HTTP/2.0" 301 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/127.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
craudiovizai
2026-09-28 06:30:43
(5 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
π³π±
ParaBug
2026-09-25 10:08:09
(1 week ago)
104.22.109.81 - - [25/Sep/2026:12:08:09 +0200] "GET /.git/config HTTP/2.0" 404 358 "-" "Wget/1.21.3 ...
show more
104.22.109.81 - - [25/Sep/2026:12:08:09 +0200] "GET /.git/config HTTP/2.0" 404 358 "-" "Wget/1.21.3 (linux-gnu)"
...
show less
Phishing
Brute-Force
Web App Attack
Anonymous
2026-09-24 18:59:44
(1 week ago)
[Thu Sep 24 20:59:43.539342 2026] [authz_core:error] [pid 2157] [client 104.22.109.81:10076] AH01630 ...
show more
[Thu Sep 24 20:59:43.539342 2026] [authz_core:error] [pid 2157] [client 104.22.109.81:10076] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Sep 24 20:59:43.580600 2026] [authz_core:error] [pid 2157] [client 104.22.109.81:10076] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Sep 24 20:59:43.615670 2026] [authz_core:error] [pid 2157] [client 104.22.109.81:10076] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π«π·
dynamix
2026-09-23 21:35:01
(1 week ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-22 22:43:14
(1 week ago)
(caddyscan) Scanner path probe from 104.22.109.81 (NL/The Netherlands/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 104.22.109.81 (NL/The Netherlands/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.109.81 - - [22/Sep/2026:22:43:04 +0000] "GET /.env%0d%0a HTTP/1.1"
[REDACTED] 200 2627 104.22.109.81 - - [22/Sep/2026:22:43:11 +0000] "GET /.env?import&raw&_=30139 HTTP/1.1"
[REDACTED] 200 2627 104.22.109.81 - - [22/Sep/2026:22:43:11 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 104.22.109.81 - - [22/Sep/2026:22:43:11 +0000] "GET /.env.local?raw HTTP/1.1"
[REDACTED] 200 2627 104.22.109.81 - - [22/Sep/2026:22:43:12 +0000] "GET /.env.local?import&raw HTTP/1.1"
show less
Port Scan