🇺🇸
Presence
2026-08-27 18:00:06
(2 days ago)
Bad bot, attempting to find exploits
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 11:41:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:41:31.413922 2026] [security2:error] [pid 6410:tid 6410] [client 104.28.228.81:22838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stricklinranch.com"] [uri "/.git/config"] [unique_id "apAia0cRyElGYDn7UvZOUgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
etu brutus
2026-08-27 10:44:04
(2 days ago)
104.28.228.81 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-08-27 10:35:51
(2 days ago)
[27/Aug/2026:13:35:50 +0300] -- 104.28.228.81 Ban reason: Scanner [SENSITIVE_FILES] | Request: HEAD ...
show more
[27/Aug/2026:13:35:50 +0300] -- 104.28.228.81 Ban reason: Scanner [SENSITIVE_FILES] | Request: HEAD /config.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇩🇪
sdos.es
2026-08-27 10:08:40
(2 days ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /.env"
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 09:34:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:34:33.011594 2026] [security2:error] [pid 12241:tid 12256] [client 104.28.228.81:10752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royalfellows.com"] [uri "/.env.local"] [unique_id "apAEqcS9P09TgWZkJSSnkwAAAIU"], referer: https://www.google.com/search?q=royalfellows.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-08-27 09:22:02
(2 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 104.28.228.81 (US/United States/-): 1 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 104.28.228.81 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.28.228.81 - - [27/Aug/2026:11:21:57 +0200] "HEAD /wp-config.php.bak HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36" "-" host=safetyacademyaspi.com
show less
Port Scan
🇺🇸
TPI-Abuse
2026-08-27 08:50:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:50:10.808254 2026] [security2:error] [pid 18421:tid 18421] [client 104.28.228.81:9578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "richardpetersbooks.com"] [uri "/.env.backup"] [unique_id "ao_6QuztqzQbgu86EbHTQQAAAAA"], referer: https://www.google.com/search?q=richardpetersbooks.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 08:19:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:19:35.713805 2026] [security2:error] [pid 7755:tid 7755] [client 104.28.228.81:54138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rkm.biz"] [uri "/.env.old"] [unique_id "ao_zF1Rot76Qrk998Le2tAAAABM"], referer: https://www.google.com/search?q=rkm.biz
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-27 08:06:02
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
nyt
2026-08-27 07:16:45
(2 days ago)
Sensitive File Probe
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 07:11:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:11:12.145230 2026] [security2:error] [pid 19637:tid 19637] [client 104.28.228.81:23971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pjbruner.com"] [uri "/.env.dist"] [unique_id "ao_jEPlasrvFoRQa9krmJAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
yvoictra
2026-08-27 06:33:13
(2 days ago)
104.28.228.81 - - [27/Aug/2026:08:33:12 +0200] "HEAD /.env.old HTTP/1.1" 404 0 "https://www.google.c ...
show more
104.28.228.81 - - [27/Aug/2026:08:33:12 +0200] "HEAD /.env.old HTTP/1.1" 404 0 "https://www.google.com/search?q=pihole.medusa.tibbus.uyiatha.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
104.28.228.81 - - [27/Aug/2026:08:33:12 +0200] "HEAD /.env.production.local HTTP/1.1" 404 0 "https://www.google.com/search?q=pihole.medusa.tibbus.uyiatha.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
104.28.228.81 - - [27/Aug/2026:08:33:12 +0200] "HEAD /.pypirc HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
104.28.228.81 - - [27/Aug/2026:08:33:12 +0200] "HEAD /.env.development.local HTTP/1.1" 404 0 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
104.28.228.81 - - [27/Aug/2026:08:33:12 +0200] "HEAD /.netrc HTTP/1.1" 404 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML,
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 06:26:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.228.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:25:52.336398 2026] [security2:error] [pid 1847580:tid 1847585] [client 104.28.228.81:43245] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photo.gallery.the-aquifer.com"] [uri "/.env"] [unique_id "ao_YcPQbIeZJGPt3jUe25AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-08-17 04:23:14
(1 week ago)
[17/Aug/2026:07:23:14 +0300] -- 104.28.228.81 Ban reason: Scanner [CMS_GENERIC] | Request: HEAD /.en ...
show more
[17/Aug/2026:07:23:14 +0300] -- 104.28.228.81 Ban reason: Scanner [CMS_GENERIC] | Request: HEAD /.env.development.local HTTP/1.1
show less
Bad Web Bot
Web App Attack