Anonymous
2026-09-09 17:32:39
(1 hour ago)
8.228.16.165 - - [09/Sep/2026:14:32:38 -0300] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env? ...
show more
8.228.16.165 - - [09/Sep/2026:14:32:38 -0300] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 403 829 "https://blogmania.com.br/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GrokBot/1.0; +https://x.ai/grokbot"
8.228.16.165 - - [09/Sep/2026:14:32:38 -0300] "GET /@fs/.env.production?raw?? HTTP/1.1" 403 829 "https://blogmania.com.br/@fs/.env.production?raw??" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:133.1) Gecko/20100101 Firefox/133.1; compatible; GPTBot/1.2; +https://openai.com/gptbot"
8.228.16.165 - - [09/Sep/2026:14:32:38 -0300] "GET /.env?raw?? HTTP/1.1" 403 829 "https://blogmania.com.br/@fs/../.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)"
8.228.16.165 - - [09/Sep/2026:14:32:38 -0300] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 829 "https://blogmania.com.br/@fs/src/.env?raw??" "Mozilla/5.0 AppleW
...
show less
Port Scan
🇬🇧
consul.to
2026-09-09 17:28:48
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
debestelapp
2026-09-09 16:40:12
(2 hours ago)
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-09 15:25:09
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-09 14:28:34
(4 hours ago)
[09/Sep/2026:17:28:34 +0300] -- 8.228.16.165 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@ ...
show more
[09/Sep/2026:17:28:34 +0300] -- 8.228.16.165 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@fs/app/.env?raw?? HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-09 14:18:10
(4 hours ago)
Bad behaviour
Web Spam
🇹🇭
thaizone.com
2026-09-09 14:12:40
(4 hours ago)
Hacking attempts against websites (D1) #1
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-09 13:50:12
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.16.165 (165.16.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.16.165 (165.16.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:50:07.968877 2026] [security2:error] [pid 29086:tid 29086] [client 8.228.16.165:7920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.livegoodherbs.com"] [uri "/@fs/.env"] [unique_id "aqFkD10iXecsM1h_SRByygAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:08:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.16.165 (165.16.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.16.165 (165.16.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:08:32.381507 2026] [security2:error] [pid 27847:tid 27847] [client 8.228.16.165:61476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hogs.whodatnation.com"] [uri "/@fs/src/.env"] [unique_id "aqFaUP3TQBJS0OYCfxwYpAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:42:35
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.16.165 (165.16.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.16.165 (165.16.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:42:31.391034 2026] [security2:error] [pid 11640:tid 11640] [client 8.228.16.165:31292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.groupof12.com"] [uri "/@fs/.env.local"] [unique_id "aqFUN9GnmosdhsKTuYE_TQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-09 12:35:55
(6 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇩🇪
Vegascosmetics
2026-09-09 12:23:29
(6 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 82>=65, Abuse 94, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
gamabe
2026-09-09 11:37:30
(7 hours ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
🇺🇸
TPI-Abuse
2026-09-09 10:40:47
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.16.165 (165.16.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.16.165 (165.16.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:40:43.966058 2026] [security2:error] [pid 31462:tid 31462] [client 8.228.16.165:2330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.infiniteliving.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqE3q2LXd-MXV0oZNtcOjAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
miszterx.hu
2026-09-09 10:34:23
(8 hours ago)
XORP (haproxy): 47x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 47x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack