๐บ๐ธ
Al Coholic
2026-09-10 03:22:13
(3 weeks ago)
Automated report (2026-09-10T15:22:13+12:00). Caught masquerading as Amazonbot.
Bad Web Bot
๐บ๐ธ
paulo.apoloni
2026-09-10 00:38:20
(3 weeks ago)
207.175.80.145 - - [09/Sep/2026:21:38:19 -0300] "GET /static../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 ...
show more
207.175.80.145 - - [09/Sep/2026:21:38:19 -0300] "GET /static../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/148.0.5137.153 Mobile Safari/537.36"
207.175.80.145 - - [09/Sep/2026:21:38:20 -0300] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; WhatsApp/10.0.2.1"
207.175.80.145 - - [09/Sep/2026:21:38:20 -0300] "GET /app/.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.5865.59 Mobile Safari/537.36; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php"
207.175.80.145 - - [09/Sep/2026:21:38:20 -0300] "GET /.aws/credentials HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Google-Extended/1.0; +http://www.google.com/bot.html"
207.175.80.145 - - [09/Sep/2026:21:38:20 -0300]
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
tjs
2026-09-09 21:25:00
(3 weeks ago)
web attack
Hacking
Web App Attack
Anonymous
2026-09-09 14:07:01
(3 weeks ago)
[ns1.moussaspartners.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/static../.env | ...
show more
[ns1.moussaspartners.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/static../.env | /@fs/proc/1/environ?raw?? | /@fs/root/.config/gcloud/application_default_credentials.json?raw??
show less
Hacking
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-09 13:21:06
(3 weeks ago)
(CT) IP 207.175.80.145 (BE/Belgium/145.80.175.207.bc.googleusercontent.com) found to have 688 connec ...
show more
(CT) IP 207.175.80.145 (BE/Belgium/145.80.175.207.bc.googleusercontent.com) found to have 688 connections
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 13:13:14
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 207.175.80.145 (145.80.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.80.145 (145.80.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:13:10.090483 2026] [security2:error] [pid 21012:tid 21012] [client 207.175.80.145:11186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.158"] [uri "/app/.env"] [unique_id "aqFbZpDt5EMyDhSAzdmCkAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-09-09 12:27:16
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
defkev
2026-09-09 10:50:11
(3 weeks ago)
Attempted Administrator Privilege Gain, Web Application Attack, Attempted Information Leak
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-09 10:50:04
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 207.175.80.145 (145.80.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.80.145 (145.80.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:49:59.193451 2026] [security2:error] [pid 6071:tid 6071] [client 207.175.80.145:17944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.10"] [uri "/static../.env"] [unique_id "aqE516VOQSJPGBSlMqRQzwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 08:17:21
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 207.175.80.145 (145.80.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.80.145 (145.80.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:17:16.836545 2026] [security2:error] [pid 1889:tid 1889] [client 207.175.80.145:20990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.169"] [uri "/static../.env"] [unique_id "aqEWDF86pqcUeHLByf1cLwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 07:03:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 207.175.80.145 (145.80.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.80.145 (145.80.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:03:07.907119 2026] [security2:error] [pid 32767:tid 32767] [client 207.175.80.145:5058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.149"] [uri "/static../.env"] [unique_id "aqEEq3LgOb2w9W7FPrbj3wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
diego
2026-09-09 05:43:55
(3 weeks ago)
[probe-44-49] 2026-09-09 05:25:27, Client: 207.175.80.145, Protocol: 6, Unauthorized activity to HTT ...
show more
[probe-44-49] 2026-09-09 05:25:27, Client: 207.175.80.145, Protocol: 6, Unauthorized activity to HTTP: GET /
show less
Web App Attack
Anonymous
2026-09-09 04:10:05
(3 weeks ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-09 02:54:41
(3 weeks ago)
denied traffic to a honeypot network. destination port 8443.
Port Scan
Hacking
Anonymous
2026-09-09 02:52:45
(3 weeks ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack