๐ง๐ช
boxed-it
2026-07-25 18:36:14
(1 day ago)
GET /.git/HEAD (Tarpitted for 1d15h8m29s, wasted 8.06MB)
Web App Attack
๐ฎ๐ช
eyesilyurt
2026-07-15 04:09:58
(1 week ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐ฉ๐ช
ValtonTahiri
2026-07-04 08:17:26
(3 weeks ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=104.22.24.85; proto=TCP; source_port=13657; target_port=8443; flags=SYN
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-20 03:53:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 23:52:49.232541 2026] [security2:error] [pid 32379:tid 32379] [client 104.22.24.85:10960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackstarmgmt.mydobdate.net"] [uri "/.env.dist"] [unique_id "ajYOkcisernB87O4MzsLkgAAABQ"], referer: https://www.google.com/search?q=blackstarmgmt.mydobdate.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 08:16:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 04:16:40.661516 2026] [security2:error] [pid 10826:tid 10826] [client 104.22.24.85:14127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brychta.net"] [uri "/.env"] [unique_id "ajT66NMEvbtLfaU8QLlBNAAAAAA"], referer: https://www.google.com/search?q=brychta.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
eyesilyurt
2026-06-15 11:02:51
(1 month ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐บ๐ธ
mnsf
2026-06-15 00:11:13
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฉ๐ช
acadeova
2026-06-01 06:15:31
(1 month ago)
๐จ Recon detected (nft drop)
SRC=104.22.24.85
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journa ...
show more
๐จ Recon detected (nft drop)
SRC=104.22.24.85
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-30 06:50:27
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 02:50:19.859460 2026] [security2:error] [pid 24687:tid 24687] [client 104.22.24.85:10219] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chassell.info|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chassell.info"] [uri "/terraform.tfstate.backup"] [unique_id "ahqIq2Xvh9lmrMHJKAx0DgAAAAI"], referer: https://www.google.com/search?q=chassell.info
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 20:46:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 16:46:07.168361 2026] [security2:error] [pid 11013:tid 11013] [client 104.22.24.85:9805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ryszardwycisk.com"] [uri "/.git/config"] [unique_id "af-dD08LwTExg_1VYcxCUQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 18:40:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 14:40:19.106164 2026] [security2:error] [pid 31931:tid 31931] [client 104.22.24.85:11606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konar-steenberg.com"] [uri "/.git/config"] [unique_id "af9_k5DPRB3W8xz5YQM1xwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 15:54:18
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 11:54:14.045161 2026] [security2:error] [pid 32676:tid 32676] [client 104.22.24.85:13520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "delicatessefoods.com"] [uri "/.git/config"] [unique_id "af9YpilIpL3gXpXMSfyv5gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 12:17:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.24.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 08:17:36.498793 2026] [security2:error] [pid 18080:tid 18080] [client 104.22.24.85:11313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnprimerano.com"] [uri "/.git/config"] [unique_id "af8l4EDmGvNCIO5LRlEdEQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
eyesilyurt
2026-04-24 10:04:23
(3 months ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐ธ๐ฌ
pusathosting.com
2026-04-09 02:00:05
(3 months ago)
24ds22 bruteforce
Brute-Force
Web App Attack