๐บ๐ธ
etu brutus
2026-07-25 12:58:38
(3 hours ago)
104.28.222.131 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐ฟ๐ฆ
conure
2026-07-25 09:15:42
(7 hours ago)
csagent: score 18.3: secrets grab x2; 2 domain(s) in 32s
Web App Attack
๐ฆ๐บ
Bay13
2026-07-25 09:06:28
(7 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
Anonymous
2026-07-25 08:21:33
(8 hours ago)
Automated vulnerability scanning and sensitive file probing against a secured web server. Attempted ...
show more
Automated vulnerability scanning and sensitive file probing against a secured web server. Attempted access to sensitive configuration files and common vulnerability paths.
show less
Brute-Force
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-25 06:00:00
(10 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
Baking333
2026-07-24 18:53:45
(21 hours ago)
[redacted] 104.28.222.131 - - [24/Jul/2026:19:53:41 +0100] "GET /.[redacted] HTTP/1.1" 302 6783 0/48 ...
show more
[redacted] 104.28.222.131 - - [24/Jul/2026:19:53:41 +0100] "GET /.[redacted] HTTP/1.1" 302 6783 0/48324 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://[redacted]/bot)" [redacted] 104.28.222.131 - - [24/Jul/2026:19:53:41 +0100] "GET / HTTP/1.1" 200 14031 0/94914 "https://[redacted]/.[redacted]" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://[redacted]/bot)"
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 17:45:03
(22 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
ambor
2026-07-24 17:06:17
(23 hours ago)
Honeypot access: Git configuration file access attempt. Path: /.git/config
Web App Attack
๐ซ๐ท
Baking333
2026-07-24 16:53:34
(23 hours ago)
[redacted] 104.28.222.131 - - [24/Jul/2026:17:53:32 +0100] "HEAD /.[redacted] HTTP/1.1" 302 1154 0/4 ...
show more
[redacted] 104.28.222.131 - - [24/Jul/2026:17:53:32 +0100] "HEAD /.[redacted] HTTP/1.1" 302 1154 0/44628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" [redacted] 104.28.222.131 - - [24/Jul/2026:17:53:32 +0100] "HEAD /.env HTTP/1.1" 302 1154 0/47554 "https://[redacted]/search?q=[redacted]" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:39:37
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:39:32.070817 2026] [security2:error] [pid 4843:tid 4843] [client 104.28.222.131:17047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baughman.org"] [uri "/.env.production"] [unique_id "amOVRLOrlrDFiXmrLNt7RQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2026-07-24 16:16:34
(1 day ago)
2026/07/25 01:16:27 [error] 299993#299993: *65801 open() "/Web/join/sitemap.xml" failed (2: No such ...
show more
2026/07/25 01:16:27 [error] 299993#299993: *65801 open() "/Web/join/sitemap.xml" failed (2: No such file or directory), client: 104.28.222.131, server: www.kinsei.jp, request: "GET /sitemap.xml HTTP/2.0", host: "www.kinsei.jp", referrer: "https://kinsei.jp/sitemap.xml"
2026/07/25 01:16:30 [error] 299993#299993: *65792 open() "/Web/join/sitemap_index.xml" failed (2: No such file or directory), client: 104.28.222.131, server: www.kinsei.jp, request: "GET /sitemap_index.xml HTTP/2.0", host: "www.kinsei.jp", referrer: "https://kinsei.jp/sitemap_index.xml"
2026/07/25 01:16:33 [error] 299993#299993: *65801 open() "/Web/join/sitemap-index.xml" failed (2: No such file or directory), client: 104.28.222.131, server: www.kinsei.jp, request: "GET /sitemap-index.xml HTTP/2.0", host: "www.kinsei.jp", referrer: "https://kinsei.jp/sitemap-index.xml"
show less
Brute-Force
Web Spam
๐ซ๐ฎ
6kilowatti
2026-07-24 16:07:32
(1 day ago)
[24/Jul/2026:16:07:18 +0000] - 404 404 - GET https rupikonnaliisa.6kw.fi "/.env.backup" [Client 104. ...
show more
[24/Jul/2026:16:07:18 +0000] - 404 404 - GET https rupikonnaliisa.6kw.fi "/.env.backup" [Client 104.28.222.131] [Length 4606] [Gzip 3.94] [Sent-to 10.144.0.13] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "https://www.google.com/search?q=rupikonnaliisa.6kw.fi"
[24/Jul/2026:16:07:18 +0000] - 404 404 - GET https rupikonnaliisa.6kw.fi "/.env.local" [Client 104.28.222.131] [Length 4606] [Gzip 3.94] [Sent-to 10.144.0.13] "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36" "-"
[24/Jul/2026:16:07:18 +0000] - 404 404 - GET https rupikonnaliisa.6kw.fi "/wp-config.php.bak" [Client 104.28.222.131] [Length 4606] [Gzip 3.94] [Sent-to 10.144.0.13] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "https://www.google.com/search?q=rupikonnaliisa.6kw.fi"
[24/Jul/2026:16:07:31 +0000] - 404 404 -
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-07-24 13:08:50
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-24 12:23:29
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 104.28.222.131 - - [24/Jul/2026:15:23:28 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 104.28.222.131 - - [24/Jul/2026:15:23:28 +0300] "HEAD /.env.bak HTTP/1.1" 403 5429 "https://www.google.com/search?q=avx.gr" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
show less
Web App Attack
Anonymous
2026-07-24 12:14:17
(1 day ago)
Repeated automated attempts to access prohibited paths and exploit known web application vulnerabili ...
show more
Repeated automated attempts to access prohibited paths and exploit known web application vulnerabilities.
show less
Bad Web Bot
Web App Attack