๐ฉ๐ช
gadix
2026-06-18 13:25:39
(3 days ago)
[18/Jun/2026:15:25:38.994878 +0200] ajPx0uyl7sa1O_hOwvHQZgAAAAo 104.234.32.95 33080 127.0.0.1 7081
[ ...
show more
[18/Jun/2026:15:25:38.994878 +0200] ajPx0uyl7sa1O_hOwvHQZgAAAAo 104.234.32.95 33080 127.0.0.1 7081
[18/Jun/2026:15:25:39.179208 +0200] ajPx0-yl7sa1O_hOwvHQZwAAAAM 104.234.32.95 33086 127.0.0.1 7081
[18/Jun/2026:15:25:39.332242 +0200] ajPx0-yl7sa1O_hOwvHQaAAAABY 104.234.32.95 33102 127.0.0.1 7081
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-06-18 01:09:50
(4 days ago)
Login Too Frequent (6)
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-17 01:21:03
(5 days ago)
15 attempts against mh-modsecurity-ban on pf221101
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-05-24 17:17:24
(4 weeks ago)
[SunMay2419:17:21.3918312026][security2:error][pid2842812:tid2842866][client104.234.32.95:0]ModSecur ...
show more
[SunMay2419:17:21.3918312026][security2:error][pid2842812:tid2842866][client104.234.32.95:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.simireinigung.ch\"][uri\"/wp-login.php\"][unique_id\"ahMyobJy-HjymAtx8c8xXwAAAFE\"]\,referer:https://www.simireinigung.ch/wp-admin/
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
akasolutions.de
2026-05-23 04:44:48
(4 weeks ago)
(wordpress) Failed wordpress login from 104.234.32.95 (US/United States/-)
Brute-Force
๐ซ๐ฎ
bittiguru.fi
2026-05-23 03:08:57
(4 weeks ago)
104.234.32.95 - [23/May/2026:05:59:59 +0300] "POST /wp-login.php HTTP/1.1" 403 3144 "https://ereijon ...
show more
104.234.32.95 - [23/May/2026:05:59:59 +0300] "POST /wp-login.php HTTP/1.1" 403 3144 "https://ereijonen.fi/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "3.24"
104.234.32.95 - [23/May/2026:06:01:34 +0300] "POST /wp-login.php HTTP/1.1" 404 5817 "https://ereijonen.fi/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "3.89"
104.234.32.95 - [23/May/2026:06:03:45 +0300] "POST /wp-login.php HTTP/1.1" 404 5817 "https://ereijonen.fi/wp-admin/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" "3.89"
104.234.32.95 - [23/May/2026:06:05:01 +0300] "POST /wp-login.php HTTP/1.1" 404 5817 "https://ereijonen.fi/wp-admin/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.1 Safari/605.1.15" "3.89"
104.234.32.95 - [23/May/2026:06:08:56
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
nyt
2026-05-23 02:19:05
(4 weeks ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 03:06:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 23:06:27.643115 2026] [security2:error] [pid 8684:tid 8684] [client 104.234.32.95:61563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.powerkiteforum.com"] [uri "/.git/config"] [unique_id "ae7Ss25X9WclZFCZZ9jPLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 01:18:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 21:18:43.973235 2026] [security2:error] [pid 26640:tid 26640] [client 104.234.32.95:44117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nancyscafeandcatering.com"] [uri "/.env.dev"] [unique_id "ae65c8PbEuViRQdbFGlxjQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-04-27 00:32:46
(1 month ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 00:14:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 20:14:21.748454 2026] [security2:error] [pid 7929:tid 7929] [client 104.234.32.95:31317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oualierealty.com"] [uri "/.env.swp"] [unique_id "ae6qXUMzxClA7hSgpA8eUwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-04-26 23:58:12
(1 month ago)
Accessed trap at '/docker-compose.yml'
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-04-13 22:25:26
(2 months ago)
Brute-Force
Web App Attack
๐ซ๐ฎ
misfit
2026-04-13 15:33:04
(2 months ago)
Web scan (5 x 404);Malicious paths: /.env,/.env.old,/.env.save. Org: AS206092 F.N.S. HOLDINGS LIMITE ...
show more
Web scan (5 x 404);Malicious paths: /.env,/.env.old,/.env.save. Org: AS206092 F.N.S. HOLDINGS LIMITED, Chicago, US.
show less
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
macrob
2026-04-13 08:16:33
(2 months ago)
2026/04/13 08:16:31 [error] 303335#303335: *147933851 access forbidden by rule, client: 104.234.32.9 ...
show more
2026/04/13 08:16:31 [error] 303335#303335: *147933851 access forbidden by rule, client: 104.234.32.95, server: fn.binixo.es, request: "POST /.env HTTP/1.1", host: "172.104.245.160"
2026/04/13 08:16:31 [error] 303335#303335: *147933851 access forbidden by rule, client: 104.234.32.95, server: fn.binixo.es, request: "GET /.env HTTP/1.1", host: "172.104.245.160"
2026/04/13 08:16:31 [error] 303335#303335: *147933851 access forbidden by rule, client: 104.234.32.95, server: fn.binixo.es, request: "GET /.env.save HTTP/1.1", host: "172.104.245.160"
...
show less
Web App Attack