๐ฉ๐ช
burlacu.org
2026-07-23 00:27:01
(4 minutes ago)
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 2 attempts ...
show more
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 2 attempts. Blocked automatically.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-07-22 22:15:53
(2 hours ago)
(caddyscan) Scanner path probe from 104.28.195.191 (NO/Norway/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 104.28.195.191 (NO/Norway/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.28.195.191 - - [22/Jul/2026:22:15:50 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 104.28.195.191 - - [22/Jul/2026:22:15:51 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 104.28.195.191 - - [22/Jul/2026:22:15:51 +0000] "GET /.aws/config HTTP/1.1"
[REDACTED] 200 2627 104.28.195.191 - - [22/Jul/2026:22:15:52 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 104.28.195.191 - - [22/Jul/2026:22:15:52 +0000] "GET /.env.production HTTP/1.1"
show less
Port Scan
๐ฎ๐น
CoreTech srl
2026-07-22 06:43:57
(17 hours ago)
cloudlinux2 fail2ban: 2026-07-22 08:39:03,101 fail2ban.filter [1589]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-22 08:39:03,101 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 104.28.195.191 - 2026-07-22 08:39:03cloudlinux2 fail2ban: 2026-07-22 08:39:06,462 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 104.28.195.191 - 2026-07-22 08:39:06cloudlinux2 fail2ban: 2026-07-22 08:39:04,744 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 104.28.195.191 - 2026-07-22 08:39:04cloudlinux2 fail2ban: 2026-07-22 08:39:06,712 fail2ban.actions [1589]: NOTICE [plesk-modsecurity] Ban 104.28.195.191cloudlinux2 fail2ban: 2026-07-22 08:39:06,718 fail2ban.filter [1589]: INFO [recidive] Found 104.28.195.191 - 2026-07-22 08:39:06cloudlinux2 fail2ban: 2026-07-22 08:40:26,267 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 45.132.227.30 - 2026-07-22 08:40:25cloudlinux2 fail2ban: 2026-07-22 08:41:16,081 fail2ban.actions [1589]: NOTICE [plesk-modsecurity] Unban 212.34.23.115cloudlinux2 fail2ban: 2026-07-22 08:41:10,215 f
show less
FTP Brute-Force
Web App Attack
๐ณ๐ฑ
javierin
2026-07-22 05:34:35
(18 hours ago)
104.28.195.191 - console.javierin.com - - [22/Jul/2026:05:34:33 +0000] "GET / HTTP/2.0" 200 4557 "-" ...
show more
104.28.195.191 - console.javierin.com - - [22/Jul/2026:05:34:33 +0000] "GET / HTTP/2.0" 200 4557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
104.28.195.191 - console.javierin.com - - [22/Jul/2026:05:34:34 +0000] "GET /.aws/credentials HTTP/2.0" 404 2509 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; +mailto:[email protected] "
...
show less
Web App Attack
Hacking
๐จ๐ฑ
SinaiCL
2026-07-22 03:55:13
(20 hours ago)
WAF Multiple Hits
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 03:02:02
(21 hours ago)
[_admin] auto-suppressed-foreign: auto: foreign suppressed offender [US, cloudflare-shared-egress]
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 00:24:22
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.28.195.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.28.195.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 20:24:18.918116 2026] [security2:error] [pid 85881:tid 85881] [client 104.28.195.191:12556] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oauth.kemela.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oauth.kemela.com"] [uri "/rclone.conf"] [unique_id "amANsj0Dk_HXPbTOITZYJAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xpto
2026-07-21 23:31:11
(1 day ago)
Blocked for probing for web application vulnerabilities
Web App Attack
๐ฎ๐น
alessio loto
2026-07-21 20:04:28
(1 day ago)
WAF Detection: Security_Scanner_Blocked (High Risk IP). AI Confirmed Attack Payload.
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-07-21 18:29:55
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 104.28.195.191 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 104.28.195.191 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐ต๐ฑ
dzpk
2026-07-21 18:29:11
(1 day ago)
104.28.195.191 - - [21/Jul/2026:20:29:10 +0200] "GET /wp-json HTTP/2.0" 404 258 "-" "Mozilla/5.0 (co ...
show more
104.28.195.191 - - [21/Jul/2026:20:29:10 +0200] "GET /wp-json HTTP/2.0" 404 258 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-07-21 18:27:33
(1 day ago)
104.28.195.191 - - [21/Jul/2026:20:27:33 +0200] "GET /.gitconfig HTTP/2.0" 404 314 "-" "Mozilla/5.0 ...
show more
104.28.195.191 - - [21/Jul/2026:20:27:33 +0200] "GET /.gitconfig HTTP/2.0" 404 314 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 104.28.195.191 - - [21/Jul/2026:20:27:33 +0200] "GET /.git/HEAD HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" 104.28.195.191 - - [21/Jul/2026:20:27:33 +0200] "GET /.git/config HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
show less
Brute-Force
๐ณ๐ฑ
e.fierstra
2026-07-21 17:46:27
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-21 07:54:42
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 104.28.195.191 (US/United States/Califo ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.28.195.191 (US/United States/California/Los Angeles/-)
show less
SQL Injection
Anonymous
2026-07-20 16:31:33
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host