๐บ๐ธ
TPI-Abuse
2026-08-26 16:42:48
(22 minutes ago)
(mod_security) mod_security (id:949110) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:42:41.924673 2026] [security2:error] [pid 23065:tid 23065] [client 8.228.11.212:43442] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.alliancegroupga.com"] [uri "/.git/HEAD"] [unique_id "ao8XgfeA2NGpj53dayE5xQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 13:40:45
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:40:39.878276 2026] [security2:error] [pid 31917:tid 31917] [client 8.228.11.212:29934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.restaurant-napkins.com"] [uri "/.env"] [unique_id "ao7s1-HUu7-YIagRLwXZFAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-08-26 13:34:09
(3 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-08-26T13:34:01.471481418Z. Context: http_status=404
show less
Web App Attack
๐ซ๐ท
masterguru
2026-08-26 12:40:54
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-26 12:29:36
(4 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-26 12:03:07
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-26 11:36:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:36:10.950866 2026] [security2:error] [pid 22225:tid 22225] [client 8.228.11.212:31666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feathersolar.com"] [uri "/app/.env"] [unique_id "ao7PqgvldLYWfB5jAfXT8wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:47:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:47:08.307593 2026] [security2:error] [pid 3547:tid 3547] [client 8.228.11.212:4930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thommesen.net"] [uri "/.git/HEAD"] [unique_id "ao7ELDknJVK20drLqI_GoAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-26 10:30:29
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ซ๐ท
Octopuce
2026-08-26 10:15:38
(6 hours ago)
Aggressive web search of vulnerable pages: /.env /static../.env /media../.env /.env.local /api/.env ...
show more
Aggressive web search of vulnerable pages: /.env /static../.env /media../.env /.env.local /api/.env ...
show less
Web App Attack
๐ซ๐ท
COMAITE
2026-08-26 10:09:38
(6 hours ago)
Common web attack from 8.228.11.212.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:04:26
(7 hours ago)
(mod_security) mod_security (id:211190) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:211190) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:04:19.045051 2026] [security2:error] [pid 21906:tid 21906] [client 8.228.11.212:60492] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||sipco.cl|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sipco.cl"] [uri "/"] [unique_id "ao66Iwo5qlAcheeJZb-TPgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:49:11
(7 hours ago)
(mod_security) mod_security (id:211190) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:211190) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:49:03.677674 2026] [security2:error] [pid 10188:tid 10188] [client 8.228.11.212:44792] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||cornerstonecharitablescholarshiptrust.org|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cornerstonecharitablescholarshiptrust.org"] [uri "/"] [unique_id "ao62j0QF6DZkzexBXIs0JgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:14:14
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.11.212 (212.11.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:14:07.207087 2026] [security2:error] [pid 3721626:tid 3722019] [client 8.228.11.212:40740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mateo-lawyers.com"] [uri "/media../.env"] [unique_id "ao6uXy9xSXm2d86yf1WjRwAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
marten_o
2026-08-26 08:51:59
(8 hours ago)
8.228.11.212 - - [26/Aug/2026:10:51:59 +0200] "GET /admin/config?cmd=cat+/root/.aws/credentials HTTP ...
show more
8.228.11.212 - - [26/Aug/2026:10:51:59 +0200] "GET /admin/config?cmd=cat+/root/.aws/credentials HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Bytespider; +https://zhanzhang.toutiao.com/)" 1940 1775
...
show less
Web App Attack