๐ฉ๐ช
mr.joecat
2026-05-08 02:42:31
(4 months ago)
142.93.124.2 - - [08/May/2026:04:42:30 +0200] "GET /composer.json HTTP/1.1" 404 555 "http://109.250. ...
show more
142.93.124.2 - - [08/May/2026:04:42:30 +0200] "GET /composer.json HTTP/1.1" 404 555 "http://109.250.139.57/composer.json" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0 Safari/537.36"
142.93.124.2 - - [08/May/2026:04:42:30 +0200] "GET /sitemap.xml HTTP/1.1" 404 555 "http://109.250.139.57/sitemap.xml" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0 Safari/537.36"
142.93.124.2 - - [08/May/2026:04:42:30 +0200] "GET /.env HTTP/1.1" 404 555 "http://109.250.139.57/.env" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0 Safari/537.36"
142.93.124.2 - - [08/May/2026:04:42:30 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 555 "http://109.250.139.57/.well-known/security.txt" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0 Safari/537.36"
142.93.124.2 - - [08/May/2026:04:42:30 +0200] "GET /robots.txt HTTP/1.1" 404 555 "http://109.250.139.57/robots.t
...
show less
Web App Attack
๐บ๐ธ
Rip
2026-05-08 02:31:52
(4 months ago)
Automated recon attempt targeting restricted and sensitive paths.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 02:04:28
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 142.93.124.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 142.93.124.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 22:04:22.080853 2026] [security2:error] [pid 8876:tid 8876] [client 142.93.124.2:56592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/composer.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/composer.json"] [unique_id "af1EpunLvjJg2a18wkBK-gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 22:09:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 142.93.124.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 142.93.124.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 18:09:05.667499 2026] [security2:error] [pid 23020:tid 23020] [client 142.93.124.2:48838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/composer.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.9"] [uri "/composer.json"] [unique_id "af0NgT1iBC8_zuZfX-rJkQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐น
rncbc
2026-05-07 22:08:39
(4 months ago)
[Thu May 07 23:08:32.171535 2026] [authz_core:error] [pid 704956:tid 704956] [client 142.93.124.2:37 ...
show more
[Thu May 07 23:08:32.171535 2026] [authz_core:error] [pid 704956:tid 704956] [client 142.93.124.2:37226] AH01630: client denied by server configuration: /srv/www/vhosts/rncbc/.htpasswd, referer: https://79.169.193.30/.htpasswd
[Thu May 07 23:08:32.222571 2026] [authz_core:error] [pid 704957:tid 704957] [client 142.93.124.2:37262] AH01630: client denied by server configuration: /srv/www/vhosts/rncbc/.htaccess, referer: https://79.169.193.30/.htaccess
[Thu May 07 23:08:38.811300 2026] [authz_core:error] [pid 704956:tid 704956] [client 142.93.124.2:37226] AH01630: client denied by server configuration: /srv/www/vhosts/rncbc/server-status, referer: https://79.169.193.30/server-status
...
show less
Brute-Force
Bad Web Bot
Web App Attack
SSH
๐บ๐ธ
jormaster3k
2026-05-07 21:46:08
(4 months ago)
Attack against Apache (too many 404s)
Web App Attack
๐ณ๐ฑ
Savvii
2026-05-07 21:36:09
(4 months ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Markus Woegerbauer
2026-05-07 16:56:00
(4 months ago)
(mod_security) mod_security triggered on hostname [redacted] 142.93.124.2 (US/United States/-)
SQL Injection
๐จ๐ฆ
Slackin' Jack
2026-05-07 16:04:34
(4 months ago)
Unauthorized scraper/crawler on port 80/443. (142.93.124.2)
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-05-04 21:59:19
(4 months ago)
Auto-ban: 12 malicious requests on 2026-05-03 (e.g., env/backup probes, brute-force, or error bursts ...
show more
Auto-ban: 12 malicious requests on 2026-05-03 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-03 22:01:16
(4 months ago)
Auto-ban: >3000 req/min op 2026-05-03
Web App Attack
SSH
Hacking
๐ฉ๐ช
LRob
2026-05-03 05:45:06
(4 months ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-05-03 05:30:04
(4 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
Anonymous
2026-05-03 05:23:51
(4 months ago)
PAD: Scan_404 detected
Bad Web Bot
๐บ๐ธ
WellSpring
2026-05-03 05:16:38
(4 months ago)
wordpress scan on 409.today/wp-login.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack