Anonymous
2026-07-25 08:30:02
(13 hours ago)
suspicious request in access.log
Web App Attack
๐จ๐ญ
TheCoon
2026-07-25 00:00:12
(22 hours ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฉ๐ช
grassau.com
2026-07-24 20:46:12
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 195.85.115.68 (GB/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 195.85.115.68 (GB/United Kingdom/England/London/-)
show less
Bad Web Bot
๐ฉ๐ช
todix
2026-07-24 20:29:11
(1 day ago)
Web App Attack Exploid from 195.85.115.68
Web App Attack
Anonymous
2026-07-24 19:41:57
(1 day ago)
195.85.115.68 - - [24/Jul/2026:21:41:57 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 AppleWe ...
show more
195.85.115.68 - - [24/Jul/2026:21:41:57 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.1; +https:///gptbot"
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-24 19:16:36
(1 day ago)
[Sat Jul 25 05:16:36.142886 2026] [security2:error] [pid 685500] [client 195.85.115.68:33242] [clien ...
show more
[Sat Jul 25 05:16:36.142886 2026] [security2:error] [pid 685500] [client 195.85.115.68:33242] [client 195.85.115.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/.env"] [unique_id "amO6FG7mqOg6nW4G_Pq8eAAAAAg"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:14:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.85.115.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 195.85.115.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:14:25.412600 2026] [security2:error] [pid 1711567:tid 1711579] [client 195.85.115.68:44036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teritemme.com"] [uri "/.env"] [unique_id "amO5kd6DKJ1oEfpHe8iBWQAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 18:21:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.85.115.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 195.85.115.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 14:21:41.030327 2026] [security2:error] [pid 707115:tid 707115] [client 195.85.115.68:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernbroadcast.com"] [uri "/.env"] [unique_id "amOtNT_nam2Moh2__dr_igAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-24 15:02:12
(1 day ago)
[Sat Jul 25 01:02:12.031408 2026] [security2:error] [pid 664468] [client 195.85.115.68:46678] [clien ...
show more
[Sat Jul 25 01:02:12.031408 2026] [security2:error] [pid 664468] [client 195.85.115.68:46678] [client 195.85.115.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.info"] [uri "/.env"] [unique_id "amN-dGhivPv_9MQvh5Ao2wAAAAw"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 13:53:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.85.115.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 195.85.115.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:53:08.847888 2026] [security2:error] [pid 4063239:tid 4063239] [client 195.85.115.68:52206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.link"] [uri "/.env"] [unique_id "amNuRDtjv1fKnEPBvcd3fwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 13:33:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.85.115.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 195.85.115.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:33:38.592142 2026] [security2:error] [pid 26837:tid 26940] [client 195.85.115.68:60696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rawhabitat.com"] [uri "/.env"] [unique_id "amNpsguzPDsQUTPTOIvhtgAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack