π©πͺ
altenglaner
2026-09-30 01:47:39
(15 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
π²πΎ
Rizzy
2026-09-26 03:01:50
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
Gabriel Camargo
2026-09-21 08:59:18
(1 week ago)
104.23.176.6 - - [21/Sep/2026:03:53:45 -0500] "GET /.env.save HTTP/1.1" 301 178 "https://www.google. ...
show more
104.23.176.6 - - [21/Sep/2026:03:53:45 -0500] "GET /.env.save HTTP/1.1" 301 178 "https://www.google.com/search?q=ipscomerbas.isismaweb.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
104.23.176.6 - - [21/Sep/2026:03:53:46 -0500] "GET /.pypirc HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
104.23.176.6 - - [21/Sep/2026:03:59:18 -0500] "GET /config.yml HTTP/1.1" 301 178 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
SSH
π©πͺ
ger-stg-sifi1
2026-09-20 23:34:37
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
lime
2026-09-19 19:43:49
(1 week ago)
104.23.176.6 - - [19/Sep/2026:19:43:49 +0000] "GET /.aws/config HTTP/1.1" 200 2741 "-" "Mozilla/5.0 ...
show more
104.23.176.6 - - [19/Sep/2026:19:43:49 +0000] "GET /.aws/config HTTP/1.1" 200 2741 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Hacking
Web App Attack
πΊπΈ
johnkarlhill
2026-09-13 11:22:05
(2 weeks ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
π©πͺ
FeG Deutschland
2026-09-09 06:52:29
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
ger-stg-sifi1
2026-09-08 17:50:37
(3 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
neckaralb-admin.de
2026-09-08 09:03:49
(3 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-06 11:32:34
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.176.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.176.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 07:32:21.457465 2026] [security2:error] [pid 24572:tid 24572] [client 104.23.176.6:10591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wethepeoplealliance.org.rejuvenationsystems.com"] [uri "/.env.development.local"] [unique_id "ap1PRYgIT05Xq3wTvFDOqAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-05 22:01:34
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
π©πͺ
FeG Deutschland
2026-08-18 02:09:07
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 23:24:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.176.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.176.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:24:48.326415 2026] [security2:error] [pid 28428:tid 28428] [client 104.23.176.6:12214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.crescentcitycafe.org"] [uri "/.git/HEAD"] [unique_id "aoOYQGRTb2QIvdy94O2bMwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 07:21:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.176.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.176.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:21:14.971594 2026] [security2:error] [pid 18828:tid 18828] [client 104.23.176.6:10461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.evelynkay.com"] [uri "/.git/config"] [unique_id "aoK2arCVWHLElT1BJRwpywAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 04:57:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.176.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.176.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:57:44.414023 2026] [security2:error] [pid 26125:tid 26125] [client 104.23.176.6:10369] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.economy-cleaners.com"] [uri "/.git/HEAD"] [unique_id "aoKUyDc3UMoeRLpfP3BCGQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack