๐ฌ๐ง
gws-hostmaster
2026-07-24 23:56:04
(19 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 10): Restricted File Access Attempt;Restricted File Access Att ...
show more
ModSecurity OWASP CRS (Anomaly Score: 10): Restricted File Access Attempt;Restricted File Access Attempt: AI Coding Assistant Artifact;URL file extension is restricted by policy;
show less
Web App Attack
๐ฌ๐ง
Oakley
2026-07-24 22:07:34
(21 hours ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐ณ๐ฑ
e.fierstra
2026-07-24 21:47:22
(21 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-07-24 11:02:11
(1 day ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐จ๐ญ
4server
2026-07-24 10:58:44
(1 day ago)
[FriJul2412:58:38.0994812026][security2:error][pid3072815:tid3073121][client104.28.195.189:0]ModSecu ...
show more
[FriJul2412:58:38.0994812026][security2:error][pid3072815:tid3073121][client104.28.195.189:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cybertelgroup.com\"][uri\"/.env.staging\"][unique_id\"amNFXpfqi8w0USEcKiEd8AAAAQ8\"]
show less
Hacking
Web App Attack
๐ท๐บ
DZBOT
2026-07-24 09:42:43
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฎ๐น
sssrit
2026-07-24 09:41:28
(1 day ago)
104.28.195.189 - - [24/Jul/2026:11:41:27 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 46454 "-" "Moz ...
show more
104.28.195.189 - - [24/Jul/2026:11:41:27 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 46454 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
...
show less
Web App Attack
๐ซ๐ท
Lunix
2026-07-24 08:08:38
(1 day ago)
Brute-Force
Web App Attack
๐ฎ๐ฉ
David Koswari
2026-07-24 05:15:00
(1 day ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ฉ๐ช
gadix
2026-07-23 20:35:38
(1 day ago)
[23/Jul/2026:22:35:33.690781 +0200] amJ7FcbGmALoV0PdJA6Q8gAAARA 104.28.195.189 48028 127.0.0.1 7080
...
show more
[23/Jul/2026:22:35:33.690781 +0200] amJ7FcbGmALoV0PdJA6Q8gAAARA 104.28.195.189 48028 127.0.0.1 7080
[23/Jul/2026:22:35:36.961525 +0200] amJ7GMbGmALoV0PdJA6Q9wAAARE 104.28.195.189 48102 127.0.0.1 7080
[23/Jul/2026:22:35:37.410259 +0200] amJ7GX6FA0V67AdUVQOGDAAAANQ 104.28.195.189 48112 127.0.0.1 7080
...
show less
Web App Attack
Anonymous
2026-07-23 19:58:39
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
Operator873
2026-07-23 19:56:12
(1 day ago)
2026/07/23 14:56:09 [error] 122567#0: *2231133 access forbidden by rule, client: 104.28.195.189, ser ...
show more
2026/07/23 14:56:09 [error] 122567#0: *2231133 access forbidden by rule, client: 104.28.195.189, server: [OBFUSCATED], request: "GET /serviceAccountKey.json HTTP/1.1", host: "pistar.n5txl.com"
2026/07/23 14:56:09 [error] 122567#0: *2231133 access forbidden by rule, client: 104.28.195.189, server: [OBFUSCATED], request: "GET /serviceAccountKey.json HTTP/1.1", host: "pistar.n5txl.com"
2026/07/23 14:56:09 [error] 122567#0: *2231131 access forbidden by rule, client: 104.28.195.189, server: [OBFUSCATED], request: "GET /service-account.json HTTP/1.1", host: "pistar.n5txl.com"
2026/07/23 14:56:09 [error] 122567#0: *2231131 access forbidden by rule, client: 104.28.195.189, server: [OBFUSCATED], request: "GET /service-account.json HTTP/1.1", host: "pistar.n5txl.com"
2026/07/23 14:56:09 [error] 122567#0: *2231132 access forbidden by rule, client: 104.28.195.189, server: [OBFUSCATED], request: "GET /credentials.json HTTP/1.1", host: "pistar.n5txl.com"
...
show less
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-23 19:25:23
(2 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-07-23 18:34:20
(2 days ago)
(caddyscan) Scanner path probe from 104.28.195.189 (NO/Norway/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.28.195.189 (NO/Norway/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.28.195.189 - - [23/Jul/2026:18:34:13 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 104.28.195.189 - - [23/Jul/2026:18:34:15 +0000] "GET /.aws/config HTTP/1.1"
[REDACTED] 200 2627 104.28.195.189 - - [23/Jul/2026:18:34:16 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 104.28.195.189 - - [23/Jul/2026:18:34:17 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 104.28.195.189 - - [23/Jul/2026:18:34:17 +0000] "GET /.env.local HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
Marc
2026-07-23 17:35:57
(2 days ago)
104.28.195.189 - - [23/Jul/2026:19:35:57 +0200] "GET /.git/config HTTP/2.0" 404 269 "-" "Mozilla/5.0 ...
show more
104.28.195.189 - - [23/Jul/2026:19:35:57 +0200] "GET /.git/config HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" 104.28.195.189 - - [23/Jul/2026:19:35:57 +0200] "GET /wp-json HTTP/2.0" 404 269 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 104.28.195.189 - - [23/Jul/2026:19:35:57 +0200] "GET /.github/workflows/deploy.yml HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot"
show less
Brute-Force