Anonymous
2026-08-17 08:12:16
(1 week ago)
104.22.24.104 - - [17/Aug/2026:10:12:13 +0200] "GET /config/api%2ephp HTTP/1.1" 403 124 "-" "curl/8. ...
show more
104.22.24.104 - - [17/Aug/2026:10:12:13 +0200] "GET /config/api%2ephp HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [17/Aug/2026:10:12:13 +0200] "GET /config/keys%2ephp HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [17/Aug/2026:10:12:13 +0200] "GET /config/credentials%2ephp HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [17/Aug/2026:10:12:13 +0200] "GET /config/packages/stripe%2eyaml HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [17/Aug/2026:10:12:13 +0200] "GET /config/packages/stripe%2eyml HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [17/Aug/2026:10:12:14 +0200] "GET /config/packages/payum%2eyaml HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [17/Aug/2026:10:12:14 +0200] "GET /config/packages/services%2eyaml HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [17/Aug/2026:10:12:14 +0200] "GET /config/services%2eyml HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [17/Aug/2026:10:12:14 +0200] "GET /config/parameters%2eyml HTTP/1.1" 403 124
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-15 19:59:35
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-13 13:27:46
(1 week ago)
104.22.24.104 - - [13/Aug/2026:15:27:42 +0200] "GET /wiki HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22. ...
show more
104.22.24.104 - - [13/Aug/2026:15:27:42 +0200] "GET /wiki HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:42 +0200] "GET /.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:42 +0200] "GET /.env.local HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:43 +0200] "GET /.env.production HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:43 +0200] "GET /.env.staging HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:43 +0200] "GET /.env.development HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:43 +0200] "GET /.env.test HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:43 +0200] "GET /.env.testing HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:43 +0200] "GET /.env.backup HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24.104 - - [13/Aug/2026:15:27:43 +0200] "GET /.env.old HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.22.24
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 12:01:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 08:01:41.496260 2026] [security2:error] [pid 3050291:tid 3050291] [client 104.22.24.104:11029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smokeydoesit.com.pages4you.com"] [uri "/.env.production.local"] [unique_id "anxgpU9eu50Wbh6jDBz0EQAAAAg"], referer: https://www.google.com/search?q=smokeydoesit.com.pages4you.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-11 14:29:33
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ช
madeit
2026-08-09 23:42:54
(2 weeks ago)
Web App Attack
๐ธ๐ฌ
wulan17
2026-08-01 14:10:22
(3 weeks ago)
Fail2ban: Web bot/vulnerability scanning detected.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-29 16:13:16
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 12:13:08.331474 2026] [security2:error] [pid 2793399:tid 2793399] [client 104.22.24.104:13266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glaswood.com"] [uri "/.git/config"] [unique_id "amomlGZHhxTp8cZMq83JZAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 04:10:11
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 00:10:04.442009 2026] [security2:error] [pid 1670611:tid 1670618] [client 104.22.24.104:11451] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafm.us"] [uri "/.git/HEAD"] [unique_id "aml9HJx8GJbZCilkLA-mDQAAAUM"], referer: https://www.google.com/search?q=aafm.us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
dyln
2026-07-12 06:42:42
(1 month ago)
Dyls honeypot brute-force: proto8 (2 total hits)
Brute-Force
๐ฆ๐บ
dyln
2026-07-08 22:31:24
(1 month ago)
Dyls honeypot brute-force: proto8 (1 total hits)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-17 01:13:02
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 21:12:56.451733 2026] [security2:error] [pid 1481:tid 1499] [client 104.22.24.104:11960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jd-web-designs.com"] [uri "/.env.dist"] [unique_id "ajH0mOl6MHEehRvge7v8WgAAAc8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-16 22:01:00
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-16
Web App Attack
SSH
Hacking
๐ฏ๐ต
Kinsei Engineering Inc.
2026-05-15 17:35:16
(3 months ago)
UFW:High-frequency access to unused ports
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-09 20:20:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 16:20:33.820678 2026] [security2:error] [pid 20955:tid 20955] [client 104.22.24.104:11732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "no504.com"] [uri "/.git/config"] [unique_id "af-XEey_xJFbdzsKbOll-AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack