๐ซ๐ท
900cm
2026-07-23 07:50:48
(1 hour ago)
[Thu Jul 23 09:50:38.390697 2026] [access_compat:error] [pid 2826736:tid 2826736] [client 104.23.245 ...
show more
[Thu Jul 23 09:50:38.390697 2026] [access_compat:error] [pid 2826736:tid 2826736] [client 104.23.245.93:12761] AH01797: client denied by server configuration: /var/www/darkintruder/.env.bak, referer: https://www.google.com/search?q=darkintruder.fr
[Thu Jul 23 09:50:39.999743 2026] [access_compat:error] [pid 2826764:tid 2826764] [client 104.23.245.93:12678] AH01797: client denied by server configuration: /var/www/darkintruder/.aws
[Thu Jul 23 09:50:48.176287 2026] [access_compat:error] [pid 2826986:tid 2826986] [client 104.23.245.93:12685] AH01797: client denied by server configuration: /var/www/darkintruder/.netrc, referer: https://www.google.com/search?q=darkintruder.fr
...
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
lnklnx
2026-07-22 19:13:00
(13 hours ago)
www.lincolnclan.com:443 104.23.245.93 - - [22/Jul/2026:14:12:50 -0500] "GET /.env.sample HTTP/1.1" 4 ...
show more
www.lincolnclan.com:443 104.23.245.93 - - [22/Jul/2026:14:12:50 -0500] "GET /.env.sample HTTP/1.1" 401 5290 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
...
show less
Web App Attack
Anonymous
2026-07-21 09:04:02
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐น
www.tana.it
2026-07-17 17:21:41
(5 days ago)
PHP scan
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-12 04:13:55
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-07-04 06:26:59
(2 weeks ago)
CMS/framework probe: 104.23.245.93 - - [04/Jul/2026:08:26:58 +0200] "GET /.env.old HTTP/2.0" 404 162 ...
show more
CMS/framework probe: 104.23.245.93 - - [04/Jul/2026:08:26:58 +0200] "GET /.env.old HTTP/2.0" 404 162 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" asn=13335 org="Cloudflare, Inc." country=US
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-02 22:00:47
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-07-02
Web App Attack
SSH
Hacking
๐ฉ๐ช
ValtonTahiri
2026-07-01 09:16:12
(3 weeks ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=104.23.245.93; proto=TCP; source_port=10929; target_port=8443; flags=SYN
show less
Port Scan
๐บ๐ธ
wimaxnz
2026-06-21 03:28:34
(1 month ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
oncord
2026-06-20 17:58:37
(1 month ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-20 03:53:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 23:52:52.559568 2026] [security2:error] [pid 32344:tid 32344] [client 104.23.245.93:9345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackstarmgmt.com.mydobdate.net"] [uri "/.env.local"] [unique_id "ajYOlD57QmFaHaHDVnTKEwAAAAQ"], referer: https://www.google.com/search?q=blackstarmgmt.com.mydobdate.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wimaxnz
2026-06-20 03:40:26
(1 month ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_sus_ua
Brute-Force
SSH
Port Scan
๐บ๐ธ
wimaxnz
2026-06-20 01:54:25
(1 month ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-17 04:49:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 00:49:28.729190 2026] [security2:error] [pid 15980:tid 15980] [client 104.23.245.93:11464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "watsonstentsandevents.com"] [uri "/.env.local"] [unique_id "ajInWLf7QR0srFCq2Iy3hwAAABA"], referer: https://www.google.com/search?q=watsonstentsandevents.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 22:42:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 18:42:18.250568 2026] [security2:error] [pid 23719:tid 23719] [client 104.23.245.93:12658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spacebooger.com.mms-boss.net"] [uri "/.env.dist"] [unique_id "ajHRSqqt0yiy0IKRhEofDQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack