๐ง๐ท
maviei
2026-06-04 15:12:16
(19 hours ago)
2026-06-04T12:12:13.619230-03:00 srv1251771 kernel: [352765.498690] [UFW BLOCK] IN=eth0 OUT= MAC=40: ...
show more
2026-06-04T12:12:13.619230-03:00 srv1251771 kernel: [352765.498690] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.253.33 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=37000 DF PROTO=TCP SPT=10900 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-04T12:12:14.629419-03:00 srv1251771 kernel: [352766.509701] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.253.33 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=37001 DF PROTO=TCP SPT=10900 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-04T12:12:15.652437-03:00 srv1251771 kernel: [352767.532781] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.253.33 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=37002 DF PROTO=TCP SPT=10900 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
Anonymous
2026-05-26 08:22:12
(1 week ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
wimaxnz
2026-05-12 03:48:22
(3 weeks ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-03 03:27:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 23:27:45.820665 2026] [security2:error] [pid 24066:tid 24066] [client 104.23.253.33:9942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whaletailbikini.com"] [uri "/.env.local.backup"] [unique_id "ac8zsbwXm_zkPyZLStlzOAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-26 01:05:26
(2 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-23 03:05:41
(2 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-22 02:05:46
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:29:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:29:47.611761 2026] [security2:error] [pid 31410:tid 31539] [client 104.23.253.33:11164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thatspecial.com"] [uri "/.env.old"] [unique_id "ab30iyvecK1zcH-t6w6w0wAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-21 00:17:01
(2 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
Anonymous
2026-03-20 20:17:24
(2 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-20 18:08:02
(2 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:27:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:27:51.040682 2026] [security2:error] [pid 28083:tid 28083] [client 104.23.253.33:14294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lobibilisim.com"] [uri "/.envrc"] [unique_id "abz290ZJPNLez1FacbTc7wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:09:37
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:09:30.413859 2026] [security2:error] [pid 14160:tid 14160] [client 104.23.253.33:9540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.villagestoner.com"] [uri "/docker/.env"] [unique_id "abzyqvQEaC6wlbt3kqfijQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:29:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:29:31.507121 2026] [security2:error] [pid 15293:tid 15322] [client 104.23.253.33:10711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.touficcorban.com"] [uri "/var/www/html/.env"] [unique_id "abzpS_4mvRWZAXB9BK3BggAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:46:28
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:46:21.497410 2026] [security2:error] [pid 1153:tid 1153] [client 104.23.253.33:11200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.watlab.com"] [uri "/.env.production.local"] [unique_id "abzfLYdIZXezx6yILrmQDAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack