π³π±
BlueWire Hosting
2026-09-30 08:51:06
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-29 23:05:19
(1 day ago)
Blocked: Reason='Suspicious traffic score=65 (review-based detection)'; Requests=3
Hacking
π³π±
Alt255
2026-09-29 14:16:18
(2 days ago)
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 178.128.220.224 - - [29/Sep/2026:16:16:15 +0200] "GET /.aws/credentials HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
ger-stg-sifi1
2026-09-28 17:14:49
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π³π±
Alt255
2026-09-26 19:24:00
(4 days ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 178 ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 178.128.220.224 - - \[26/Sep/2026:21:23:48 +0200\] "GET /.env.dist HTTP/1.1" 404 5838 "https://long-wildflower-374b.qambtpnf.workers.dev/proxy\?modify\&proxyUrl=http%3A%2F%2Fbxlsysteembouw.nl%2F.env.dist" "Mozilla/5.0 \(Linux\; Android 14\; Pixel 8\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/135.0.6422.113 Mobile Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 03:22:56
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
πͺπΈ
robotstxt
2026-09-25 23:19:03
(5 days ago)
178.128.220.224 - - [25/Sep/2026:23:18:41 +0000] "GET /.aws/credentials HTTP/1.1" 403 15423 "https:/ ...
show more
178.128.220.224 - - [25/Sep/2026:23:18:41 +0000] "GET /.aws/credentials HTTP/1.1" 403 15423 "https://www.javiercasares.net/.aws/credentials" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0" "-" edge="178.128.220.224"
178.128.220.224 - - [25/Sep/2026:23:18:41 +0000] "GET /config.json HTTP/1.1" 403 15423 "https://www.javiercasares.net/config.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "-" edge="178.128.220.224"
178.128.220.224 - - [25/Sep/2026:23:18:42 +0000] "GET /.env.backup HTTP/1.1" 403 15423 "https://www.javiercasares.net/.env.backup" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36" "-" edge="178.128.220.224"
178.128.220.224 - - [25/Sep/2026:23:18:44 +0000] "GET /.env.dist HTTP/1.1" 403 77571 "https://www.javiercasares.net/.env.dist" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatibl
...
show less
Web App Attack
π©πͺ
ger-stg-sifi1
2026-09-24 09:07:58
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π¨π
backslash
2026-09-24 01:06:02
(1 week ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
π³π±
e.fierstra
2026-09-23 02:06:31
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π«π·
/dev/null
2026-09-22 17:16:14
(1 week ago)
Web attack | malicious scanning detected.
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 06:04:43
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 178.128.220.224 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 178.128.220.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:04:35.152021 2026] [security2:error] [pid 12565:tid 12565] [client 178.128.220.224:0] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hamiltonbookings.com"] [uri "/.env.local"] [unique_id "arDI8zDbJsQfZWqabou18wAAAD8"], referer: https://www.google.com/search?q=hamiltonbookings.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-20 15:55:44
(1 week ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 178.128.220.224 - - [20/Sep/2026:17:55:25 +0200] "GET /.git/HEAD HTTP/2.0" 403 69 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-15 18:04:08
(2 weeks ago)
[ti-01ov] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 178 ...
show more
[ti-01ov] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 178.128.220.224 - - [09/Sep/2026:18:16:09 +0200] "GET /.env.dist HTTP/1.1" 404 103966 "https://raspy-feather-3fbd.njwq3799.workers.dev/proxy?modify&proxyUrl=https%3A%2F%2Fwww.maplegroup.nl%2F.env.dist" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
178.128.220.224 - - [09/Sep/2026:18:16:09 +0200] "GET /.env.local HTTP/1.1" 404 103966 "https://muddy-moon-b80b.66qhuw2p.workers.dev/proxy?modify&proxyUrl=https%3A%2F%2Fwww.maplegroup.nl%2F.env.local" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
178.128.220.224 - - [09/Sep/2026:18:16:10 +0200] "GET /.env HTTP/1.1" 404 103966 "https://m
...
show less
Bad Web Bot
Web App Attack
π©πͺ
Blexyel
2026-09-15 03:22:35
(2 weeks ago)
178.128.220.224 - - [15/Sep/2026:05:22:35 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "ureq/2.12. ...
show more
178.128.220.224 - - [15/Sep/2026:05:22:35 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "ureq/2.12.1"
...
show less
Brute-Force
Web App Attack