๐ซ๐ท
arsonist
2026-09-13 18:07:35
(18 hours ago)
[fail2ban]
2026-09-13T18:07:34.871695+00:00 arson caddy[1890453]: {"level":"info","ts":1789322854.87 ...
show more
[fail2ban]
2026-09-13T18:07:34.871695+00:00 arson caddy[1890453]: {"level":"info","ts":1789322854.8716018,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.71.99.72","remote_port":"10637","client_ip":"172.71.99.72","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/.git/config","headers":{"Accept-Encoding":["gzip, br"],"Cdn-Loop":["cloudflare; loops=1"],"X-Forwarded-For":["45.148.10.21"],"Cf-Ray":["a3a917a2df5a670f-AMS"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"],"Cf-Connecting-Ip":["45.148.10.21"],"Cf-Ipcountry":["NL"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"X-Forwarded-Proto":["https"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"ayuworks.xyz","ech":false}},"bytes_read":0,"user_id":"","duration":0.00018548,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc"
...
show less
Bad Web Bot
๐ซ๐ท
arsonist
2026-09-10 05:24:39
(4 days ago)
[fail2ban]
2026-09-10T05:24:38.443020+00:00 arson caddy[1890453]: {"level":"info","ts":1789017878.44 ...
show more
[fail2ban]
2026-09-10T05:24:38.443020+00:00 arson caddy[1890453]: {"level":"info","ts":1789017878.442848,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.71.99.72","remote_port":"11688","client_ip":"172.71.99.72","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/.env","headers":{"Cf-Visitor":["{\"scheme\":\"https\"}"],"X-Forwarded-For":["45.148.10.140"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"],"Accept":["*/*"],"Cdn-Loop":["cloudflare; loops=1"],"Cf-Connecting-Ip":["45.148.10.140"],"Cf-Ipcountry":["NL"],"Cf-Ray":["a38c01ec3d8a0b48-AMS"],"Accept-Encoding":["gzip, br"],"X-Forwarded-Proto":["https"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"ayuworks.xyz","ech":false}},"bytes_read":0,"user_id":"","duration":0.000184218,"si
...
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-09-05 22:01:22
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
๐ซ๐ท
arsonist
2026-09-03 23:31:17
(1 week ago)
[fail2ban]
2026-09-03T23:31:16.080045+00:00 arson caddy[1890453]: {"level":"info","ts":1788478276.07 ...
show more
[fail2ban]
2026-09-03T23:31:16.080045+00:00 arson caddy[1890453]: {"level":"info","ts":1788478276.0799973,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.71.99.72","remote_port":"14318","client_ip":"172.71.99.72","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/app/.env","headers":{"Sec-Fetch-Site":["none"],"Cache-Control":["no-cache"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Mode":["navigate"],"X-Forwarded-For":["93.123.109.103"],"Cf-Connecting-Ip":["93.123.109.103"],"Upgrade-Insecure-Requests":["1"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"],"Accept-Encoding":["gzip, br"],"Sec-Ch-Ua-Full-Version-List":["\"Chromium\";v=\"136.0.7103.114\", \"Google Chrome\";v=\"136.0.7103.114\", \"Not-A.Brand\";v=\"99.0.0.0\""],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0
...
show less
Bad Web Bot
๐ง๐ช
madeit
2026-08-19 20:23:33
(3 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-11 02:47:35
(1 month ago)
Web App Attack
๐บ๐ธ
FreeMyIP
2026-07-16 09:39:52
(1 month ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
๐บ๐ธ
FreeMyIP
2026-07-06 19:08:43
(2 months ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-06-19 08:10:06
(2 months ago)
172.71.99.72 - - [19/Jun/2026:02:10:06 -0600] "GET /.git/config HTTP/2.0" 300 4342 "-" "Mozilla/5.0 ...
show more
172.71.99.72 - - [19/Jun/2026:02:10:06 -0600] "GET /.git/config HTTP/2.0" 300 4342 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Web App Attack
๐บ๐ธ
mawan
2026-06-19 02:43:39
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 05:26:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.99.72 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.99.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 01:26:36.152561 2026] [security2:error] [pid 7346:tid 7365] [client 172.71.99.72:13511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.toubaomaha.com"] [uri "/.env.development"] [unique_id "ahPdjNpY8HEqbJ9zjKFcNwAAAMc"], referer: https://www.google.com/search?q=mail.toubaomaha.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-05-20 01:17:01
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
ParaBug
2026-05-17 01:56:35
(3 months ago)
172.71.99.72 - - [17/May/2026:03:56:35 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 563 "- ...
show more
172.71.99.72 - - [17/May/2026:03:56:35 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 563 "-" "http://myviven.org/wp-admin/install.php?step=1"
...
show less
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
wimaxnz
2026-05-16 01:37:35
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐ฆ๐บ
trentwiles.com
2026-05-07 13:33:10
(4 months ago)
Unauthorized connection attempt detected from IP address 172.71.99.72 to port 80 [SYD]
Port Scan