๐ฎ๐ฉ
securejdprop
2026-08-21 07:11:41
(6 hours ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-05 18:31:52
(2 weeks ago)
Web App Attack
Anonymous
2026-08-04 05:44:02
(2 weeks ago)
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 weeks ago)
Apache probe; attempts=16; exact paths: /.env | /.env.bak | /.env.local | /.git/HEAD | /.openclaw/.e ...
show more
Apache probe; attempts=16; exact paths: /.env | /.env.bak | /.env.local | /.git/HEAD | /.openclaw/.env | /actuator | /actuator/configprops | /actuator/mappings | /admin/.env | /api/.env | /backend/.env | /config/.env | /config/.env.php | /core/.env
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 20:54:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 16:54:10.861498 2026] [security2:error] [pid 25895:tid 25895] [client 104.22.24.231:10119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tiffanyshouses.com"] [uri "/.env.development.local"] [unique_id "amkW8jAn3jr-x0ACqr0S4gAAAAY"], referer: https://www.google.com/search?q=tiffanyshouses.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-07-15 23:09:54
(1 month ago)
/.aws/credentials
Hacking
Web App Attack
๐บ๐ธ
mawan
2026-07-10 05:30:30
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 07:44:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 03:44:24.602581 2026] [security2:error] [pid 21860:tid 21970] [client 104.22.24.231:12271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crosstheatreorg.pwrcoupling.com"] [uri "/.env.dist"] [unique_id "ajeWWAWA2nKbsaKdkTTeNgAAAgo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 02:51:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 22:51:13.612517 2026] [security2:error] [pid 14460:tid 14460] [client 104.22.24.231:13389] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.michaelhick.com"] [uri "/.env.production"] [unique_id "ajILoc80QQeWZ538RjJzfQAAAAU"], referer: https://www.google.com/search?q=webmail.michaelhick.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 21:59:48
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-15
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-14 10:37:17
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:37:09.165554 2026] [security2:error] [pid 8235:tid 8235] [client 104.22.24.231:12020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.otcraftworks.com"] [uri "/.env.old"] [unique_id "ai6EVb7ijONn__Ue2Idr1wAAACw"], referer: https://www.google.com/search?q=webmail.otcraftworks.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 10:12:21
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:12:08.951014 2026] [security2:error] [pid 711:tid 711] [client 104.22.24.231:14293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tdj.franchiseconsultants.org"] [uri "/.env.production"] [unique_id "ai5-eDf9OPtzmvddkLoB-AAAAAk"], referer: https://www.google.com/search?q=tdj.franchiseconsultants.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-05-19 07:16:12
(3 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ซ๐ฎ
iamxorum
2026-05-12 10:37:56
(3 months ago)
2026-05-12T10:37:55.636256+00:00 XRM-01 kernel: [HONEYPORT] IN=eth0 OUT= MAC=92:00:06:e6:da:95:d2:74 ...
show more
2026-05-12T10:37:55.636256+00:00 XRM-01 kernel: [HONEYPORT] IN=eth0 OUT= MAC=92:00:06:e6:da:95:d2:74:7f:6e:37:e3:08:00 SRC=104.22.24.231 DST=46.62.222.43 LEN=60 TOS=0x00 PREC=0x00 TTL=50 ID=29224 DF PROTO=TCP SPT=10108 DPT=8080 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-09 11:38:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 07:38:17.550332 2026] [security2:error] [pid 11593:tid 11593] [client 104.22.24.231:11250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goodideagirl.com"] [uri "/.git/config"] [unique_id "af8cqRw3PmasvZMpk4N_awAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack