๐ซ๐ท
dynamix
2026-10-01 07:26:24
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-26 10:45:06
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-09-21 11:50:05
(1 week ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ง๐ช
madeit
2026-09-18 00:25:46
(2 weeks ago)
Web App Attack
๐ซ๐ท
dynamix
2026-09-14 05:27:38
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
arsonist
2026-09-14 02:46:23
(2 weeks ago)
[fail2ban]
2026-09-14T02:46:22.877463+00:00 arson caddy[1890453]: {"level":"info","ts":1789353982.87 ...
show more
[fail2ban]
2026-09-14T02:46:22.877463+00:00 arson caddy[1890453]: {"level":"info","ts":1789353982.877428,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.71.23.75","remote_port":"13962","client_ip":"172.71.23.75","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/.env?.svg?.wasm?init","headers":{"Accept-Encoding":["gzip, br"],"Accept":["*/*"],"User-Agent":["Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"],"Cdn-Loop":["cloudflare; loops=1"],"Cf-Connecting-Ip":["34.24.54.157"],"X-Forwarded-Proto":["https"],"Cf-Ipcountry":["US"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Cf-Ray":["a3ac0f96d8c50f57-ATL"],"X-Fo
...
show less
Bad Web Bot
๐ซ๐ท
arsonist
2026-09-14 00:12:36
(2 weeks ago)
[fail2ban]
2026-09-14T00:12:35.915398+00:00 arson caddy[1890453]: {"level":"info","ts":1789344755.91 ...
show more
[fail2ban]
2026-09-14T00:12:35.915398+00:00 arson caddy[1890453]: {"level":"info","ts":1789344755.9153607,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.71.23.75","remote_port":"10973","client_ip":"172.71.23.75","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/.env?.svg?.wasm?init","headers":{"X-Forwarded-For":["34.24.54.157"],"Accept-Encoding":["gzip, br"],"Accept":["*/*"],"Cf-Ipcountry":["US"],"X-Forwarded-Proto":["https"],"Cf-Connecting-Ip":["34.24.54.157"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Cdn-Loop":["cloudflare; loops=1"],"X-Nextjs-Data":["1"],"Cf-Ray":["a3ab2e525c14dde4-ATL"],"User-Agent":["Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/
...
show less
Bad Web Bot
๐ซ๐ท
arsonist
2026-09-13 07:39:34
(2 weeks ago)
[fail2ban]
2026-09-13T07:39:34.303046+00:00 arson caddy[1890453]: {"level":"info","ts":1789285174.30 ...
show more
[fail2ban]
2026-09-13T07:39:34.303046+00:00 arson caddy[1890453]: {"level":"info","ts":1789285174.3030045,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.71.23.75","remote_port":"11088","client_ip":"172.71.23.75","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/.env?.svg?.wasm?init","headers":{"Cf-Ipcountry":["US"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"X-Forwarded-For":["34.24.54.157"],"Accept-Encoding":["gzip, br"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Cf-Connecting-Ip":["34.24.54.157"],"Accept":["*/*"],"X-Forwarded-Proto":["https"],"User-Agent":["Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"],"X-Nextjs-Data":["1"],"Cf-Ray":["a3a57fb14ffabcf5-ATL"],"Cdn-Loop":["cloud
...
show less
Bad Web Bot
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-29 16:12:00
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ช
madeit
2026-08-10 11:40:25
(1 month ago)
Web App Attack
Anonymous
2026-08-01 05:06:11
(2 months ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 15:16:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.23.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.23.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 11:16:11.420608 2026] [security2:error] [pid 3014935:tid 3014935] [client 172.71.23.75:13468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hakanararat.com"] [uri "/.env.sample"] [unique_id "amoZO1f9Kuvu-kbbrlqgtAAAAB0"], referer: https://www.google.com/search?q=hakanararat.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-28 21:59:35
(2 months ago)
Auto-ban: >3000 req/min op 2026-07-28
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-09 18:51:16
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.23.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.23.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 14:51:13.105733 2026] [security2:error] [pid 12985:tid 12985] [client 172.71.23.75:12311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "muranelli.com"] [uri "/.git/config"] [unique_id "af-CIesGjAmm5F7XP78QRwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-04-25 02:10:27
(5 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack