🇳🇱
homeshowdomain.nl
2026-09-07 21:59:36
(14 hours ago)
Auto-ban: >3000 req/min op 2026-09-07
Web App Attack
SSH
Hacking
🇺🇸
mnsf
2026-09-07 21:05:18
(15 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:23:05
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.180.80 (80.180.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.180.80 (80.180.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:22:58.906974 2026] [security2:error] [pid 16798:tid 16798] [client 8.229.180.80:59388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.i-579captiger.pghsea.com"] [uri "/@fs/.env.development"] [unique_id "ap8dIoT0kt1zKQ9TbyWYDgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 20:04:16
(16 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇨🇭
zynex
2026-09-07 19:44:21
(16 hours ago)
URL Probing: /@fs/usr/src/app/.env
Web App Attack
🇨🇭
Origon
2026-09-07 19:35:47
(17 hours ago)
http-probing - IP: 8.229.180.80 - time="2026-09-07T21:35:46+02:00" level=info msg="(555f66b4f6a7455 ...
show more
http-probing - IP: 8.229.180.80 - time="2026-09-07T21:35:46+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 8.229.180.80 (US/396982) : 4h ban on Ip 8.229.180.80" module=db
show less
Web App Attack
🇩🇪
maxpower
2026-09-07 19:16:21
(17 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 8.229.180.80 (US/United States/80.180.229.8.bc.googleuserconte ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 8.229.180.80 (US/United States/80.180.229.8.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 8.229.180.80 - - [07/Sep/2026:21:16:17 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 200 11888 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "-" host=sensationart.it.accademiam.com
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-07 18:55:49
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.180.80 (80.180.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.180.80 (80.180.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:55:44.180550 2026] [security2:error] [pid 30165:tid 30165] [client 8.229.180.80:3072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.linneus.com"] [uri "/@fs/app/.env"] [unique_id "ap8IsKnpxupDMXmtwHZd_AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 18:53:59
(17 hours ago)
2.337 requests with url.path */@fs/*
593 requests with url.path *.aws/*
226 requests with url.pat ...
show more
2.337 requests with url.path */@fs/*
593 requests with url.path *.aws/*
226 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
🇳🇱
e.fierstra
2026-09-07 18:17:21
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:12:23
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.180.80 (80.180.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.180.80 (80.180.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:12:20.433643 2026] [security2:error] [pid 28248:tid 28248] [client 8.229.180.80:53116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.morleysales.com"] [uri "/@fs/../../.env"] [unique_id "ap7-hCjZxABV5rN67oap3AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-07 18:11:25
(18 hours ago)
Web scanning / probing for vulnerable paths | URL: /@fs/app/.env?raw?? | Evidence: 8.229.180.80 - - ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/app/.env?raw?? | Evidence: 8.229.180.80 - - [07/Sep/2026:20:10:24 +0200] \"GET /@fs/app/.env?raw?? HTTP/1.1\" 404 51855 \"https://spainbytrain.info/@fs/app/.env?raw??\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http://www.linkedin.com) Chrome/122.0.1601.65 Safari/537.36 Edg/122.0.1601.65\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:30:23
(19 hours ago)
(mod_security) mod_security (id:949110) triggered by 8.229.180.80 (80.180.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 8.229.180.80 (80.180.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:30:19.071024 2026] [security2:error] [pid 32764:tid 32764] [client 8.229.180.80:2904] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "usataxgroup.com"] [uri "/@fs/.env.local"] [unique_id "ap70q7nqCBUveO5E24_B_wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 17:25:02
(19 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
tvipper.com
2026-09-07 16:53:24
(19 hours ago)
Auto reported by IDS
Brute-Force