π«π·
Flo Flo
2026-06-20 21:42:54
(1 month ago)
5.255.109.131 - - - [20/Jun/2026:23:42:54 +0200] "wildcard.flad.xyz" "GET / HTTP/1.1" 444 0 "-" "Moz ...
show more
5.255.109.131 - - - [20/Jun/2026:23:42:54 +0200] "wildcard.flad.xyz" "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; Google-CloudVertexBot; +https://cloud.google.com/vertex-ai-bot)" 0.000
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 20:33:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 16:33:27.873592 2026] [security2:error] [pid 16523:tid 16523] [client 5.255.109.131:35610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.yourmenu.xyz"] [uri "/.git/config"] [unique_id "ajb5F2_L_y-wjwBPxnX9-wAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
LRob
2026-06-20 20:15:02
(1 month ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 20:13:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 16:13:44.818151 2026] [security2:error] [pid 17014:tid 17014] [client 5.255.109.131:35012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.neuromancer.xyz"] [uri "/.git/config"] [unique_id "ajb0eBNdX0SlIA9jPrr5OQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
itsnixk
2026-06-20 19:42:55
(1 month ago)
(mod_security) mod_security (id:930130) triggered by 5.255.109.131 (NL/The Netherlands/-): 1 in the ...
show more
(mod_security) mod_security (id:930130) triggered by 5.255.109.131 (NL/The Netherlands/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Sat Jun 20 15:42:51.021605 2026] [security2:error] [pid 632045:tid 632138] [client 5.255.109.131:36140] ModSecurity: Access denied with code 406 (phase 1). Matched phrase ".aws/" at REQUEST_FILENAME. [file "/etc/modsecurity.d/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "150"] [id "930130"] [msg "Restricted File Access Attempt"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.26.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [redacted] [uri "/.aws/credentials"] [unique_id "ajbtO5VgOWhO3y0Oh3qZyQAAAAo"]
show less
Port Scan
π©πͺ
BlueWire Hosting
2026-06-20 19:41:55
(1 month ago)
Bad bot ignoring robot.txt
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-20 19:40:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 15:39:58.816497 2026] [security2:error] [pid 22762:tid 22762] [client 5.255.109.131:56616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.whatifandwhynot.xyz"] [uri "/.env.backup"] [unique_id "ajbsjr6_FBAcRANzbAK8MAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 19:20:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 15:20:26.843729 2026] [security2:error] [pid 27953:tid 27953] [client 5.255.109.131:43234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.actionplanner.xyz"] [uri "/.env.bak"] [unique_id "ajbn-qK3O5vwoSPLyk4oLwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Lezetho
2026-06-20 19:00:34
(1 month ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-20 18:13:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 14:13:06.102241 2026] [security2:error] [pid 19045:tid 19045] [client 5.255.109.131:49786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vr-squaredance.kdgsf.xyz"] [uri "/.env.production"] [unique_id "ajbYMhIkTKjY7OPs575KQgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
tutaim.com
2026-06-20 16:00:03
(1 month ago)
β [20/06/26] This IP has been detected performing multiple attacks on websites (66 attempts blocked) ...
show more
β [20/06/26] This IP has been detected performing multiple attacks on websites (66 attempts blocked). Potential malicious activity.
show less
Brute-Force
SSH
Web App Attack
FTP Brute-Force
πΊπΈ
TPI-Abuse
2026-06-20 10:19:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.109.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 06:19:02.113470 2026] [security2:error] [pid 21010:tid 21010] [client 5.255.109.131:43200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taafe.xyz"] [uri "/.git/config"] [unique_id "ajZpFtcrRvclgw4w2XmUbgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
updown.io
2026-06-20 08:29:22
(1 month ago)
{"level":"info","ts":1781943968.5049527,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1781943968.5049527,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"5.255.109.131","remote_port":"51732","client_ip":"5.255.109.131","proto":"HTTP/1.1","method":"GET","host":"status.code.wetrafa.xyz","uri":"/secrets.yml","headers":{"Accept-Language":["en-US,en;q=0.9"],"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Site":["none"],"Upgrade-Insecure-Requests":["1"],"Accept-Encoding":["gzip"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Fetch-User":["?1"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.code.wetrafa.xyz","ech":false}},"bytes_read":0,"user_id":"","duration":0.001024096,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-Afte
...
show less
DDoS Attack
Web App Attack
π³π±
Brict IT
2026-06-20 08:12:09
(1 month ago)
Bad Web Bot
Web App Attack
π¬π§
MrTumnus
2026-06-20 06:19:32
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking