๐บ๐ฆ
Olexiy Backend
2026-07-25 16:43:36
(7 hours ago)
104.28.254.133
...
Bad Web Bot
Web App Attack
๐บ๐ธ
etu brutus
2026-07-25 12:58:44
(11 hours ago)
104.28.254.133 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐ฆ๐บ
Bay13
2026-07-25 09:06:29
(14 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐บ๐ธ
xxkodedxx
2026-07-24 17:24:33
(1 day ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: CA / AS13335 Cloudflare, Inc.
Active: 17:23:46 UTC
Volume: 1 HTTP req
Probed: /aZ9xQ7kL3m
Status mix: 444ร1
Vhost fishing: cards.zvxlabs.com
UA: "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-07-24 17:06:20
(1 day ago)
Honeypot access: PHP file scan attempt: /config.php. Path: /config.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:39:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:39:32.422765 2026] [security2:error] [pid 26526:tid 26526] [client 104.28.254.133:45688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baughman.org"] [uri "/wp-config.php.bak"] [unique_id "amOVROpSw711TvArtgM7_AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-07-24 16:25:41
(1 day ago)
[Fri Jul 24 18:25:38.521877 2026] [security2:error] [pid 2242361:tid 2242366] [client 104.28.254.133 ...
show more
[Fri Jul 24 18:25:38.521877 2026] [security2:error] [pid 2242361:tid 2242366] [client 104.28.254.133:61239] [client 104.28.254.133] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.oh.mg.sus.fr"] [uri "/.env"] [unique_id "amOSAma731egQ0sTupyl3QAAAQM"], referer: https://www.google.com/search?q=www.oh.mg.sus.fr
[Fri Jul 24 18:25:40.484678 2026] [security2:error] [pid 2242361:tid 2242376] [client 104.28.254.133:11470] [client 104.28.254.133] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Sco
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
ger-stg-sifi1
2026-07-24 16:12:01
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:35:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:35:41.074677 2026] [security2:error] [pid 22780:tid 22780] [client 104.28.254.133:14100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/wp-config.php.bak"] [unique_id "amOGTc0gWJEcvm6iqKpa7wAAAAY"], referer: https://www.google.com/search?q=accordionclub.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:19:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:19:35.503881 2026] [security2:error] [pid 23002:tid 23002] [client 104.28.254.133:32242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityimprinting.abilityengraving.com"] [uri "/.env.backup"] [unique_id "amOCh-4LbJnWZRQDh064xAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:57:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:57:24.420495 2026] [security2:error] [pid 3752472:tid 3752472] [client 104.28.254.133:45979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "80corvette.com"] [uri "/.git/HEAD"] [unique_id "amN9VBeIVa1gtnFLsUEoqgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-24 12:23:28
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 104.28.254.133 - - [24/Jul/2026:15:23:28 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 104.28.254.133 - - [24/Jul/2026:15:23:28 +0300] "HEAD /.env.sample HTTP/1.1" 403 5429 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
show less
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-07-24 11:53:29
(1 day ago)
Excessive HTTP request rate
Web App Attack
๐ฉ๐ช
langenkamp-media
2026-07-24 11:36:32
(1 day ago)
Fail2Ban: Banned from jail nginx-nohome on 3dausdu.de
Web App Attack
Anonymous
2026-07-24 08:45:10
(1 day ago)
104.28.254.133 - - [24/Jul/2026:05:44:49 -0300] "GET /admin HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Wind ...
show more
104.28.254.133 - - [24/Jul/2026:05:44:49 -0300] "GET /admin HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
104.28.254.133 - - [24/Jul/2026:05:45:04 -0300] "HEAD /.env.production HTTP/1.1" 403 0 "https://topvitrine.com.br/.env.production" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
104.28.254.133 - - [24/Jul/2026:05:45:06 -0300] "HEAD /.env.test HTTP/1.1" 403 0 "https://topvitrine.com.br/.env.test" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
104.28.254.133 - - [24/Jul/2026:05:45:06 -0300] "HEAD /config.yml HTTP/1.1" 404 0 "https://topvitrine.com.br/config.yml" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
104.28.254.133 - - [24/Jul/2026:05:45:09 -0300] "HEAD /wp-config.php HTTP/1.1" 404 0 "https://www.google.com
...
show less
Port Scan