๐ซ๐ท
Baking333
2026-08-23 15:43:48
(5 hours ago)
[redacted] 104.22.56.241 - - [23/Aug/2026:16:43:42 +0100] "GET /.aws/credentials HTTP/2.0" 301 60 "- ...
show more
[redacted] 104.22.56.241 - - [23/Aug/2026:16:43:42 +0100] "GET /.aws/credentials HTTP/2.0" 301 60 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://[redacted])" [redacted] 104.22.56.241 - - [23/Aug/2026:16:43:42 +0100] "GET /.aws/config HTTP/2.0" 301 57 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://[redacted])"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ValtonTahiri
2026-08-22 17:12:11
(1 day ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=104.22.56.241; proto=TCP; source_port=10866; target_port=8080; flags=SYN
show less
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-08-15 00:31:37
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
Baking333
2026-08-13 15:14:29
(1 week ago)
[redacted] 104.22.56.241 - - [13/Aug/2026:16:14:24 +0100] "GET /.gitconfig HTTP/2.0" 301 56 "-" "Moz ...
show more
[redacted] 104.22.56.241 - - [13/Aug/2026:16:14:24 +0100] "GET /.gitconfig HTTP/2.0" 301 56 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://[redacted])" [redacted] 104.22.56.241 - - [13/Aug/2026:16:14:24 +0100] "GET /.aws/config HTTP/2.0" 301 57 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://[redacted])"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
breubit
2026-08-11 17:52:17
(1 week ago)
104.22.56.241 - - [11/Aug/2026:19:52:16 +0200] "GET /.env.production.local HTTP/1.1" 404 4474 "https ...
show more
104.22.56.241 - - [11/Aug/2026:19:52:16 +0200] "GET /.env.production.local HTTP/1.1" 404 4474 "https://www.google.com/search?q=julienbailly.ddns.net" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
...
show less
Web App Attack
๐ง๐ช
madeit
2026-08-10 04:34:42
(1 week ago)
Web App Attack
Anonymous
2026-08-04 05:44:24
(2 weeks ago)
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
2026-07-25 08:49:55
(4 weeks ago)
104.22.56.241 - - [25/Jul/2026:10:49:55 +0200] "GET /.env HTTP/2.0" 301 169 "https:///search?q=" "Mo ...
show more
104.22.56.241 - - [25/Jul/2026:10:49:55 +0200] "GET /.env HTTP/2.0" 301 169 "https:///search?q=" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-07-04 06:26:59
(1 month ago)
CMS/framework probe: 104.22.56.241 - - [04/Jul/2026:08:26:58 +0200] "GET /.env.production.local HTTP ...
show more
CMS/framework probe: 104.22.56.241 - - [04/Jul/2026:08:26:58 +0200] "GET /.env.production.local HTTP/2.0" 404 564 "https://www.google.com/search?q=assets.stateparl.de" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36" asn=13335 org="Cloudflare, Inc." country=US
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 11:13:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.56.241 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.56.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 07:13:21.639856 2026] [security2:error] [pid 21361:tid 21361] [client 104.22.56.241:13349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cageliners.net"] [uri "/.env.local"] [unique_id "ajZ10YMtJ5vHo6nR27V-gAAAAAQ"], referer: https://www.google.com/search?q=cageliners.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 22:01:04
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-15
Web App Attack
SSH
Hacking
๐บ๐ธ
mawan
2026-04-25 02:48:08
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 01:04:28
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.56.241 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.56.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 21:04:22.273447 2026] [security2:error] [pid 29314:tid 29328] [client 104.22.56.241:11787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adultbaja.com"] [uri "/.env.orig"] [unique_id "aeQqFsRt6C1IC4wAGvaoHgAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chrisj
2026-04-16 06:33:57
(4 months ago)
[Thu Apr 16 06:33:56.285201 2026] [proxy_fcgi:error] [pid 243908:tid 243908] [client 104.22.56.241:1 ...
show more
[Thu Apr 16 06:33:56.285201 2026] [proxy_fcgi:error] [pid 243908:tid 243908] [client 104.22.56.241:14014] AH01071: Got error 'Primary script unknown'
[Thu Apr 16 06:33:56.511063 2026] [proxy_fcgi:error] [pid 243908:tid 243908] [client 104.22.56.241:14014] AH01071: Got error 'Primary script unknown'
[Thu Apr 16 06:33:56.760446 2026] [proxy_fcgi:error] [pid 243908:tid 243908] [client 104.22.56.241:14014] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
myagent.site
2026-04-06 01:47:09
(4 months ago)
Blocking for trying to access an exploit file: /config/.env
Hacking