๐ง๐ช
madeit
2026-09-18 07:12:22
(4 days ago)
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-12 00:32:47
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ธ๐ฌ
securejdprop
2026-09-10 11:35:57
(1 week ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-09 05:47:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:47:38.919481 2026] [security2:error] [pid 18047:tid 18047] [client 104.22.66.221:9772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimwilsonstudios.com"] [uri "/.env"] [unique_id "aqDy-oArN7SaJx8IeyNxRwAAAA4"], referer: https://www.google.com/search?q=jimwilsonstudios.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 01:57:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:57:06.806244 2026] [security2:error] [pid 7790:tid 7790] [client 104.22.66.221:10023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianmindy.com"] [uri "/.env.local"] [unique_id "aqC88liYfd5B5sYb5BxuQQAAABM"], referer: https://www.google.com/search?q=brianmindy.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 18:22:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:22:16.674572 2026] [security2:error] [pid 9321:tid 9321] [client 104.22.66.221:12253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slmd.me"] [uri "/.env.backup"] [unique_id "aqBSWB4cA4K9KyDlbg2sGwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-04 22:01:52
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-18 01:40:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:39:57.264225 2026] [security2:error] [pid 29507:tid 29507] [client 104.22.66.221:10193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.xirination.com"] [uri "/.git/config"] [unique_id "aoO37Zikqy4AfAw6oVvSYwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 23:00:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:00:51.225710 2026] [security2:error] [pid 2766:tid 2766] [client 104.22.66.221:13474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lynnejewson.com"] [uri "/.git/HEAD"] [unique_id "aoOSo7fBhrA56OJZvC7yJgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:18:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:18:29.862748 2026] [security2:error] [pid 30693:tid 30881] [client 104.22.66.221:10025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ecocentri.city"] [uri "/.git/config"] [unique_id "aoLD1fy7geWZoWRvLvuL5gAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:44:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:44:33.800246 2026] [security2:error] [pid 4416:tid 4416] [client 104.22.66.221:13207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.barrykrueger.com"] [uri "/.git/HEAD"] [unique_id "aoK74SbGI_epokwvu25IpAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CBJ
2026-08-17 04:25:40
(1 month ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:53:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:53:01.291108 2026] [security2:error] [pid 4346:tid 4346] [client 104.22.66.221:12029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.justjunglejuice.org"] [uri "/.git/HEAD"] [unique_id "aoKFnS_yuVSrFJV6t0J-gwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:47:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:47:42.658439 2026] [security2:error] [pid 15951:tid 15951] [client 104.22.66.221:11217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.allisonstiles.org"] [uri "/.git/HEAD"] [unique_id "aoJ2Tq4Skra4PQL9TH9LwgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 01:10:56
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.66.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:10:49.216147 2026] [security2:error] [pid 15561:tid 15561] [client 104.22.66.221:11586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lo-family.org"] [uri "/.git/HEAD"] [unique_id "aoJfmXsBJfMTnuIct43uTwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack