πΊπΈ
johnkarlhill
2026-09-11 05:27:33
(16 hours ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-08-18 02:04:39
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 22:04:34.539092 2026] [security2:error] [pid 8755:tid 8755] [client 104.22.93.62:13413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hppagewideflorida.com"] [uri "/.git/config"] [unique_id "aoO9ssB4pFK55LBL-4iihAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 06:37:43
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:37:35.546026 2026] [security2:error] [pid 1287:tid 1287] [client 104.22.93.62:12808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.touchmypython.bwill.dev"] [uri "/.git/config"] [unique_id "aoKsLzs4C9Sg1bKDOdfb8wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 06:05:29
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:05:22.016540 2026] [security2:error] [pid 10864:tid 10892] [client 104.22.93.62:10639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forestfamily.coldwave.net"] [uri "/.git/config"] [unique_id "aoKkokJPM9tA3yduzl1ubgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 05:39:46
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:39:42.561304 2026] [security2:error] [pid 15317:tid 15317] [client 104.22.93.62:9903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.qovintheloop.org"] [uri "/.git/config"] [unique_id "aoKenlg3MLVTLML6GT968gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
iNetWorker
2026-08-17 05:26:08
(3 weeks ago)
trolling for resource vulnerabilities
Web App Attack
πΊπ¦
Olexiy Backend
2026-08-17 02:04:35
(3 weeks ago)
104.22.93.62
...
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 22:49:50
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:49:41.914244 2026] [security2:error] [pid 1381:tid 1381] [client 104.22.93.62:12647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.russellhouse.net"] [uri "/.git/config"] [unique_id "aoI-hX2UKSGgfMFlYdRr3gAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 10:25:09
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:25:03.971875 2026] [security2:error] [pid 19459:tid 19530] [client 104.22.93.62:10610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oswgr.wwwhst.com"] [uri "/.git/config"] [unique_id "aoGP_99aJqQ4AOdF13-iKAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-16 07:06:06
(3 weeks ago)
Trying to access config files
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 06:01:28
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:01:21.918614 2026] [security2:error] [pid 22159:tid 22159] [client 104.22.93.62:11713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.zavion.com"] [uri "/.git/HEAD"] [unique_id "aoFSMXkqocrDlXgKmCIutwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 23:34:06
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 19:34:01.114187 2026] [security2:error] [pid 4175167:tid 4175167] [client 104.22.93.62:9926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pharmasalesconnect.com"] [uri "/.git/config"] [unique_id "anuxaYUzfUmgbc9YpANxugAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ratcarcher-labs
2026-08-05 20:41:46
(1 month ago)
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=bot_scanner risk=75 attacks=23 depth= ...
show more
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=bot_scanner risk=75 attacks=23 depth=4 node=node-ap-south canary=no human_score=65 agentic=15 cc=US asn=Cloudflare, Inc. | Data provided by Ratcarcher Labs Β· https://ratcarcher-labs.com Β· docs https://api.ratcarcher-labs.com/api/v1/public/docs
show less
Port Scan
Bad Web Bot
π§πͺ
madeit
2026-08-05 08:25:26
(1 month ago)
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=27; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.example ...
show more
Apache probe; attempts=27; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.example | /.env.local | /.env.old | /.env.php.bak | /.env.production | /.env.swp | /.git-credentials | /.git/HEAD | /.git/config | /.hermes/.env | /.openclaw/.env | /actuator | /actuator/configprops | /actuator/mappings | /admin/.env | /api/.env | /backend/.env | /config/.env | /config/.env.php | /core/.env | /laravel/.env | /public/.env | /web/.env
show less
Web App Attack