๐ฌ๐ง
consul.to
2026-07-25 19:15:37
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
etu brutus
2026-07-25 12:58:38
(12 hours ago)
104.28.222.133 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-25 09:15:42
(16 hours ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 1m29s
Web App Attack
๐ฆ๐บ
Bay13
2026-07-25 09:06:28
(16 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐บ๐ธ
ambor
2026-07-24 21:28:38
(1 day ago)
Honeypot access: Database backup file access attempt. Path: /dump.sql
Web App Attack
๐ซ๐ท
Baking333
2026-07-24 18:53:35
(1 day ago)
[redacted] 104.28.222.133 - - [24/Jul/2026:19:53:34 +0100] "HEAD /.[redacted] HTTP/1.1" 302 6397 0/5 ...
show more
[redacted] 104.28.222.133 - - [24/Jul/2026:19:53:34 +0100] "HEAD /.[redacted] HTTP/1.1" 302 6397 0/56431 "https://[redacted]/search?q=[redacted]" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36" [redacted] 104.28.222.133 - - [24/Jul/2026:19:53:34 +0100] "HEAD / HTTP/1.1" 200 1138 0/86772 "https://[redacted]/.[redacted]" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:53:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:53:49.167165 2026] [security2:error] [pid 26837:tid 26940] [client 104.28.222.133:18645] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jevan.au.jevan1.com"] [uri "/.env.test"] [unique_id "amOYnQuzPDsQUTPTOIs8qQAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-07-24 16:25:44
(1 day ago)
[Fri Jul 24 18:25:39.212412 2026] [security2:error] [pid 2241860:tid 2241880] [client 104.28.222.133 ...
show more
[Fri Jul 24 18:25:39.212412 2026] [security2:error] [pid 2241860:tid 2241880] [client 104.28.222.133:36508] [client 104.28.222.133] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.oh.mg.sus.fr"] [uri "/.aws/credentials"] [unique_id "amOSA5UBRcnq_jLdjCjUawAAANI"]
[Fri Jul 24 18:25:43.050681 2026] [security2:error] [pid 2264733:tid 2264739] [client 104.28.222.133:17067] [client 104.28.222.133] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/
...
show less
Web App Attack
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-07-24 15:58:27
(1 day ago)
104.28.222.133 - - [24/Jul/2026:18:58:26 +0300] "GET /.git/HEAD HTTP/1.1" 301 567 "https://www.googl ...
show more
104.28.222.133 - - [24/Jul/2026:18:58:26 +0300] "GET /.git/HEAD HTTP/1.1" 301 567 "https://www.google.com/search?q=ee.zp.edu.ua" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
104.28.222.133 - - [24/Jul/2026:18:58:26 +0300] "GET /wp-config.php HTTP/1.1" 404 4691 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:35:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:35:41.662759 2026] [security2:error] [pid 19848:tid 19848] [client 104.28.222.133:11141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/.env.dist"] [unique_id "amOGTSbL9hq6ufyWy_wdFQAAAAo"], referer: https://www.google.com/search?q=accordionclub.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:19:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:19:39.785829 2026] [security2:error] [pid 24294:tid 24294] [client 104.28.222.133:18832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityimprinting.com"] [uri "/.env"] [unique_id "amOCiyR7EqF6W7PlviUX_AAAAAs"], referer: https://www.google.com/search?q=abilityimprinting.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:57:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:57:24.418829 2026] [security2:error] [pid 3753965:tid 3753965] [client 104.28.222.133:10544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "80corvette.com"] [uri "/wp-config.php"] [unique_id "amN9VMwtt-JlEd3f4HH2OAAAABg"], referer: https://www.google.com/search?q=80corvette.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-24 13:08:50
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-24 12:23:21
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 104.28.222.133 - - [24/Jul/2026:15:23:19 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 104.28.222.133 - - [24/Jul/2026:15:23:19 +0300] "HEAD /.git/config HTTP/1.1" 403 5429 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
show less
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-07-24 11:53:24
(1 day ago)
Excessive HTTP request rate
Web App Attack