🇪🇸
el-brujo
2026-09-12 06:33:33
(29 minutes ago)
12/Sep/2026:08:33:33.802588 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
12/Sep/2026:08:33:33.802588 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 130.211.81.164] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /@fs/../.env?raw??"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "mail.elhacker.net"] [uri "/.env"] [unique_id "aqTyPY0yl6BqgGGlSrraOQABjHo"]
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 06:29:28
(33 minutes ago)
(mod_security) mod_security (id:210730) triggered by 130.211.81.164 (164.81.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 130.211.81.164 (164.81.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:29:21.301885 2026] [security2:error] [pid 3230780:tid 3230828] [client 130.211.81.164:33082] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.earthtravel.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.earthtravel.net"] [uri "/rclone.conf"] [unique_id "aqTxQQP7n45hLl7yoQ0hFAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
NotCool
2026-09-12 06:27:15
(36 minutes ago)
[7200] (DOTENVPROBE,CRAWLDELAY) Login failure/trigger from 130.211.81.164 (BE/Belgium/164.81.211.130 ...
show more
[7200] (DOTENVPROBE,CRAWLDELAY) Login failure/trigger from 130.211.81.164 (BE/Belgium/164.81.211.130.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Brute-Force
🇳🇱
ConsulHosting
2026-09-12 06:24:39
(38 minutes ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇸🇪
SkyDancer
2026-09-12 02:30:04
(4 hours ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
🇫🇷
regishoussin
2026-09-12 01:30:28
(5 hours ago)
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-12 01:30 UTC.
show less
Bad Web Bot
Web App Attack
🇫🇷
Entalpi.net
2026-09-11 17:53:11
(13 hours ago)
Repeated requests against sensitive web endpoints
Web App Attack
🇸🇪
EmK530
2026-09-11 17:42:19
(13 hours ago)
URL flagged by RegEx: /media../.env
Web App Attack
🇦🇺
electronico
2026-09-11 17:26:59
(13 hours ago)
130.211.81.164 - - [12/Sep/2026:04:26:58 +1100] "GET /_nuxt/../.env HTTP/2.0" 404 1890 "-" "Mozilla/ ...
show more
130.211.81.164 - - [12/Sep/2026:04:26:58 +1100] "GET /_nuxt/../.env HTTP/2.0" 404 1890 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
130.211.81.164 - - [12/Sep/2026:04:26:58 +1100] "GET /files../.env HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
130.211.81.164 - - [12/Sep/2026:04:26:58 +1100] "GET /media../.env HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
130.211.81.164 - - [12/Sep/2026:04:26:58 +1100] "GET /z9x8c7v6b5-debug-trigger-electronicohost.net HTTP/2.0" 404 1854 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
130.211.81.164 - - [12/Sep/2026:04:26:58 +1100] "GET /rclone.conf HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
130.211.81.164 - - [12/Sep/2026:04:26:58 +1100] "GET /static../.env HTTP/2.0" 404 1854 "-"
...
show less
Brute-Force
Web App Attack
🇫🇮
stinpriza
2026-09-11 17:23:17
(13 hours ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:19:53
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 130.211.81.164 (164.81.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.81.164 (164.81.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:19:45.928257 2026] [security2:error] [pid 16084:tid 16084] [client 130.211.81.164:60456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ehrlichfamily.net"] [uri "/.env.local"] [unique_id "aqQ4MQNqA37KOO2ms-yoPwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 17:17:57
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
Anonymous
2026-09-11 17:09:21
(13 hours ago)
130.211.81.164 - - [12/Sep/2026:01:09:19 +0800] "GET /wp-json HTTP/1.1" 404 296486 "-" "Mozilla/5.0 ...
show more
130.211.81.164 - - [12/Sep/2026:01:09:19 +0800] "GET /wp-json HTTP/1.1" 404 296486 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
130.211.81.164 - - [12/Sep/2026:01:09:19 +0800] "GET /asset-manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
130.211.81.164 - - [12/Sep/2026:01:09:19 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
130.211.81.164 - - [12/Sep/2026:01:09:19 +0800] "GET /static/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
130.211.81.164 - - [12/Sep/2026:01:09:19 +0800] "GET /manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
...
show less
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 17:06:03
(13 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-11 16:55:31
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 130.211.81.164 (164.81.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 130.211.81.164 (164.81.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:55:25.027119 2026] [security2:error] [pid 3721:tid 3721] [client 130.211.81.164:37200] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||eagleoaks.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eagleoaks.net"] [uri "/rclone.conf"] [unique_id "aqQyfQlY6HpunncfkZOIxgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack