π©πͺ
Holger
2026-09-27 06:59:56
(20 hours ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
π³π±
Alt255
2026-09-25 21:53:01
(2 days ago)
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.23.175.17 - - [25/Sep/2026:23:52:56 +0200] "GET /.env.production HTTP/1.1" 301 479 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
webanyone
2026-09-18 13:47:48
(1 week ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
π©πͺ
webanyone
2026-09-17 21:02:27
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
π§πͺ
madeit
2026-09-15 10:50:33
(1 week ago)
Web App Attack
Anonymous
2026-09-14 16:32:52
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π©πͺ
kkw
2026-09-14 03:03:06
(2 weeks ago)
[REDACTED] 104.23.175.17 - - [14/Sep/2026:05:03:05 +0200] "GET /.git/config HTTP/2.0" 404 282227 "-" ...
show more
[REDACTED] 104.23.175.17 - - [14/Sep/2026:05:03:05 +0200] "GET /.git/config HTTP/2.0" 404 282227 "-" "-"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-11 12:30:30
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.175.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.175.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:30:21.733069 2026] [security2:error] [pid 25455:tid 25455] [client 104.23.175.17:11900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baselinesc.com"] [uri "/.env.production"] [unique_id "aqP0XaN1OUz86NTvwK7sBQAAAAI"], referer: https://www.google.com/search?q=baselinesc.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-09 11:46:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.175.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.175.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:46:08.857674 2026] [security2:error] [pid 23529:tid 23529] [client 104.23.175.17:12480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tugofwarrior.com"] [uri "/.git/config"] [unique_id "aqFHAGigPTf7khn5KT3kAgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-09 09:50:44
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.175.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.175.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:50:34.714473 2026] [security2:error] [pid 25440:tid 25440] [client 104.23.175.17:12365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rubypines.com"] [uri "/.env.production.local"] [unique_id "aqEr6t5RbhEfa13tNiFnBgAAAAc"], referer: https://www.google.com/search?q=rubypines.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-09 04:12:08
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.175.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.175.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:11:59.349472 2026] [security2:error] [pid 14887:tid 14892] [client 104.23.175.17:11637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "farmerlabor.org"] [uri "/.env.old"] [unique_id "aqDcj4pnrR67CalsbTOcoAAAAQI"], referer: https://www.google.com/search?q=farmerlabor.org
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-08 10:26:19
(2 weeks ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π¬π§
sandra361
2026-09-06 11:57:32
(3 weeks ago)
Port scan detected: 5 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=104.2 ...
show more
Port scan detected: 5 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=104.23.175.17 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=3245 DF PROTO=TCP SPT=13917 DPT=443 WINDOW=65535 RES=0x00 ACK URGP=0
show less
Port Scan
π§πͺ
madeit
2026-09-04 18:59:31
(3 weeks ago)
Web App Attack
π©πͺ
Bedios GmbH
2026-08-27 19:46:44
(1 month ago)
Login credentials theft attempt
Hacking