๐ซ๐ท
SpaceHost-Server
2026-09-20 22:15:21
(19 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:08:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:08:15.026704 2026] [security2:error] [pid 2916573:tid 2916573] [client 130.211.249.158:59360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "al-bukhari.org"] [uri "/.git/config"] [unique_id "aq_ozy0ueKrOxO3tiEHz7QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:44:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:44:34.015051 2026] [security2:error] [pid 8954:tid 8954] [client 130.211.249.158:58784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ahijado.org"] [uri "/api/v1/.env"] [unique_id "aq_jQrhtCUoi10FzvZu6-gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 13:42:26
(1 day ago)
130.211.249.158 - - [20/Sep/2026:13:41:49 +0000] "POST / HTTP/2.0" 403 33007 "-" "Mozilla/5.0 AppleW ...
show more
130.211.249.158 - - [20/Sep/2026:13:41:49 +0000] "POST / HTTP/2.0" 403 33007 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-" edge="130.211.249.158"
130.211.249.158 - - [20/Sep/2026:13:41:49 +0000] "GET /settings.json HTTP/2.0" 403 10937 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="130.211.249.158"
130.211.249.158 - - [20/Sep/2026:13:41:49 +0000] "GET /api/v1/.env HTTP/2.0" 403 11350 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="130.211.249.158"
130.211.249.158 - - [20/Sep/2026:13:41:49 +0000] "GET /.aws/credentials HTTP/2.0" 403 10957 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-" edge="130.211.249.158"
130.211.249.158 - - [20/Sep/2026:13:41:49 +0000] "GET /.env_1 HTTP/2.0" 403 10937 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-" edge="130.211.249.158"
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 13:30:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:25:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:24:59.800562 2026] [security2:error] [pid 19031:tid 19031] [client 130.211.249.158:56870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afjm.org"] [uri "/.env.js"] [unique_id "aq_eq-b_HrtX3HiVL6bgVQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 13:24:17
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-09-20 13:05:31
(1 day ago)
Web app vulnerability scanning detected. Evidence: [IP] - - [20/Sep/2026:13:05:27 +0000] "GET /dashb ...
show more
Web app vulnerability scanning detected. Evidence: [IP] - - [20/Sep/2026:13:05:27 +0000] "GET /dashboard%2F.env HTTP/1.1" 404 776 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[IP] Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
[IP] - - [20/Sep/2026:13:05:30 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 404 776 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
show less
Web App Attack
๐ซ๐ท
Octopuce
2026-09-20 12:48:23
(1 day ago)
Aggressive web search of vulnerable pages: /private/.env /static/.env /assets/.env /static../.env /v ...
show more
Aggressive web search of vulnerable pages: /private/.env /static/.env /assets/.env /static../.env /var/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:42:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:42:54.755993 2026] [security2:error] [pid 20464:tid 20464] [client 130.211.249.158:57190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/core/.env"] [unique_id "aq_UzjOXdNEeJEFTGcg7QQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lavnet.net
2026-09-20 12:16:35
(1 day ago)
130.211.249.158 - - [20/Sep/2026:12:16:35 +0000] "GET /.aws/credentials HTTP/2.0" 404 1901 "-" "Mozi ...
show more
130.211.249.158 - - [20/Sep/2026:12:16:35 +0000] "GET /.aws/credentials HTTP/2.0" 404 1901 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
130.211.249.158 - - [20/Sep/2026:12:16:35 +0000] "GET /.github/workflows/deploy.yml HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
130.211.249.158 - - [20/Sep/2026:12:16:35 +0000] "GET /.env.local HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
130.211.249.158 - - [20/Sep/2026:12:16:35 +0000] "GET /z9x8c7v6b5-debug-trigger-a0a0.org HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
130.211.249.158 - - [20/Sep/2026:12:16:35 +0000] "GET /.gitconfig HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
130.211.249.158 - - [20/Sep/2026:12:16:35 +0000] "POST /graphql HTTP/2.0" 404 1855 "https://a0a
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 11:28:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.249.158 (158.249.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:28:13.603652 2026] [security2:error] [pid 9976:tid 9976] [client 130.211.249.158:46060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4azadi.org"] [uri "/.env.production"] [unique_id "aq_DTXExYK-8Xvr-DFMHQwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 11:01:02
(1 day ago)
...
Web App Attack
๐ฉ๐ช
macrob
2026-09-20 10:40:33
(1 day ago)
2026/09/20 10:40:32 [error] 478234#478234: *17876020 access forbidden by rule, client: 130.211.249.1 ...
show more
2026/09/20 10:40:32 [error] 478234#478234: *17876020 access forbidden by rule, client: 130.211.249.158, server: 100fs.org, request: "GET /.aws/credentials HTTP/1.1", host: "100fs.org"
2026/09/20 10:40:32 [error] 478234#478234: *17875972 access forbidden by rule, client: 130.211.249.158, server: 100fs.org, request: "GET /.aws/config HTTP/1.1", host: "100fs.org"
2026/09/20 10:40:32 [error] 478234#478234: *17875993 access forbidden by rule, client: 130.211.249.158, server: 100fs.org, request: "GET /.git/HEAD HTTP/1.1", host: "100fs.org"
...
show less
Web App Attack