๐บ๐ฆ
URAN Publishing Service
2026-07-29 12:40:34
(3 weeks ago)
104.28.162.63 - - [29/Jul/2026:15:40:33 +0300] "GET /.env HTTP/1.1" 404 4742 "-" "Mozilla/5.0 (Macin ...
show more
104.28.162.63 - - [29/Jul/2026:15:40:33 +0300] "GET /.env HTTP/1.1" 404 4742 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
...
show less
Web App Attack
๐ธ๐ช
SkyDancer
2026-07-29 12:23:08
(3 weeks ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ฉ๐ช
tentwentyfour
2026-07-29 10:21:35
(3 weeks ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
Anonymous
2026-07-29 08:30:04
(3 weeks ago)
104.28.162.63 - - [29/Jul/2026:03:30:01 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (iPhone ...
show more
104.28.162.63 - - [29/Jul/2026:03:30:01 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Mobile/15E148 Safari/604.1" 104.28.162.63
104.28.162.63 - - [29/Jul/2026:03:30:01 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36" 104.28.162.63
104.28.162.63 - - [29/Jul/2026:03:30:01 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36" 104.28.162.63
104.28.162.63 - - [29/Jul/2026:03:30:01 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.0) Gecko/20100101 Firefox/150.0" 104.28.162.63
104.28.162.63 - - [29/Jul/2026:03:30:01 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-29 07:33:55
(3 weeks ago)
cloudlinux2 fail2ban: 2026-07-29 09:29:00,150 fail2ban.filter [1584]: INFO [plesk-apache] ...
show more
cloudlinux2 fail2ban: 2026-07-29 09:29:00,150 fail2ban.filter [1584]: INFO [plesk-apache] Found 114.119.145.163 - 2026-07-29 09:29:00cloudlinux2 fail2ban: 2026-07-29 09:29:56,107 fail2ban.actions [1584]: NOTICE [plesk-modsecurity] Unban 3.27.73.247cloudlinux2 fail2ban: 2026-07-29 09:31:17,634 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 34.138.162.79 - 2026-07-29 09:31:17cloudlinux2 fail2ban: 2026-07-29 09:31:14,425 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 34.138.162.79 - 2026-07-29 09:31:14cloudlinux2 fail2ban: 2026-07-29 09:31:52,387 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 104.28.162.63 - 2026-07-29 09:31:51cloudlinux2 fail2ban: 2026-07-29 09:31:55,707 fail2ban.filter [1584]: INFO [plesk-apache] Found 114.119.137.190 - 2026-07-29 09:31:55cloudlinux2 fail2ban: 2026-07-29 09:32:43,510 fail2ban.actions [1584]: NOTICE [plesk-modsecurity] Unban 151.158.235.148cloudlinux2 fail2ban: 2026-07-29 09:33:19,938
show less
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2026-07-29 06:17:49
(3 weeks ago)
104.28.162.63 - - [29/Jul/2026:09:17:46 +0300] "GET /.env HTTP/1.1" 404 4721 "-" "Mozilla/5.0 (Windo ...
show more
104.28.162.63 - - [29/Jul/2026:09:17:46 +0300] "GET /.env HTTP/1.1" 404 4721 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0"
104.28.162.63 - - [29/Jul/2026:09:17:48 +0300] "GET /.env.production HTTP/1.1" 404 788 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0"
...
show less
Web App Attack
Anonymous
2026-07-02 23:08:52
(1 month ago)
2026-07-03 01:08:51,359 fail2ban.actions [636]: NOTICE [apache-php-scans] Ban 104.28.162.63
...
show more
2026-07-03 01:08:51,359 fail2ban.actions [636]: NOTICE [apache-php-scans] Ban 104.28.162.63
2026-07-03 01:08:51,472 fail2ban.actions [636]: NOTICE [apache-custom] Ban 104.28.162.63
2026-07-03 01:08:51,587 fail2ban.actions [636]: NOTICE [apache-noscript] Ban 104.28.162.63
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
Celtic
2026-07-02 01:20:15
(1 month ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
Anonymous
2026-07-01 11:45:47
(1 month ago)
104.28.162.63 - - [01/Jul/2026:11:45:35 +0000] "GET /sa.json HTTP/1.1" 404 134 "-" "Mozilla/5.0 Appl ...
show more
104.28.162.63 - - [01/Jul/2026:11:45:35 +0000] "GET /sa.json HTTP/1.1" 404 134 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
104.28.162.63 - - [01/Jul/2026:11:45:35 +0000] "GET /v1/graphql HTTP/1.1" 404 134 "-" "anthropic-ai"
...
show less
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-01 03:28:25
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-01 04:28:25 UTC
Log evidence:
07/01/2026-04:28:24.615709 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 104.28.162.63:33124 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
๐ซ๐ท
masterguru
2026-06-30 13:18:50
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 104.28.162.63 (CA/Canada/-): 2 in the ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 104.28.162.63 (CA/Canada/-): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ฉ๐ช
FeG Deutschland
2026-06-30 07:33:03
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 03:05:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.28.162.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.162.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 23:05:30.949271 2026] [security2:error] [pid 26446:tid 26446] [client 104.28.162.63:33974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "b2c-llc.anthonyanimalclinic.net"] [uri "/.env.swp"] [unique_id "akMyenR4ZNypxZ_rFoE8VAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-30 02:09:13
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-29 23:39:31
(1 month ago)
Web attack/malicious scanning detected
Web App Attack