π¦πΊ
A.i.D.A.N.N
2026-10-05 01:25:45
(15 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-09-18 07:45:53
(2 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
π©πͺ
bescared
2026-08-11 17:35:00
(1 month ago)
WAF (1) - URL probing.
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 04:09:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.56.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.56.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 00:09:30.011507 2026] [security2:error] [pid 6562:tid 6562] [client 104.22.56.120:12564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyclelytz.com"] [uri "/.env.backup"] [unique_id "anqgev0MHs95ASifySVO9wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mawan
2026-08-10 08:50:28
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π³π±
homeshowdomain.nl
2026-07-29 22:02:44
(2 months ago)
Auto-ban: >3000 req/min op 2026-07-29
Web App Attack
SSH
Hacking
π©πͺ
bescared
2026-07-16 20:05:00
(2 months ago)
WAF (1) - URL probing.
Hacking
Bad Web Bot
Web App Attack
π«π·
sthoyer.de
2026-07-16 05:07:41
(2 months ago)
104.22.56.120 - - [16/Jul/2026:07:07:00 +0200] "GET /_rNd9xZ7kL3 HTTP/2" 302 495 "https://www.google ...
show more
104.22.56.120 - - [16/Jul/2026:07:07:00 +0200] "GET /_rNd9xZ7kL3 HTTP/2" 302 495 "https://www.google.com/search?q=cloud.sthoyer.de" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
104.22.56.120 - - [16/Jul/2026:07:07:20 +0200] "GET /sitemap_index.xml HTTP/2" 302 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
104.22.56.120 - - [16/Jul/2026:07:07:39 +0200] "GET /.env.dist HTTP/2" 302 495 "https://www.google.com/search?q=cloud.sthoyer.de" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
...
show less
Web App Attack
π©πͺ
bescared
2026-07-14 19:31:42
(2 months ago)
F2B - Malicious activity detected. URL Probing. -151302cd-
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-19 07:21:28
(3 months ago)
(mod_security) mod_security (id:949110) triggered by 104.22.56.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.22.56.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 03:21:18.696709 2026] [security2:error] [pid 5531:tid 5531] [client 104.22.56.120:11051] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "armstrongenvironmental.com"] [uri "/.env.local"] [unique_id "ajTt7vK5MTG1fT92bw7RKAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-16 23:19:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.56.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.56.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 19:19:34.734139 2026] [security2:error] [pid 17259:tid 17259] [client 104.22.56.120:12567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.matinpack.com"] [uri "/.env.production"] [unique_id "ajHaBrEdYlEIXOAocP8ZTgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 18:12:03
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.56.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.56.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 14:11:53.770978 2026] [security2:error] [pid 16557:tid 16557] [client 104.22.56.120:13656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "halblog.com"] [uri "/.env.backup"] [unique_id "ai2daZzN9IWDGQbT8OZDzAAAAAM"], referer: https://www.google.com/search?q=halblog.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-06-02 21:59:51
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-01.
show less
Web App Attack
SSH
Hacking
π©πͺ
Lazentis
2026-06-02 17:38:22
(4 months ago)
Unauthorized access attempt to port 8080 (tcp)
Brute-Force
SSH
π©πͺ
Lazentis
2026-05-09 14:36:42
(4 months ago)
Unauthorized access attempt to port 8080 (tcp)
Brute-Force
SSH