๐ณ๐ฑ
Site.eu
2026-08-08 04:27:05
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
tmiland
2026-08-08 04:20:40
(2 weeks ago)
(nginx_404s) Nginx Security rule triggered from 8.231.157.26 (US/United States/26.157.231.8.bc.googl ...
show more
(nginx_404s) Nginx Security rule triggered from 8.231.157.26 (US/United States/26.157.231.8.bc.googleusercontent.com): 50 in the last 3600 secs; IP: 8.231.157.26; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/08 06:20:36 [error] 1069336#1069336: *8999 open() "/home/abuseip/public_html/config.json" failed (2: No such file or directory), client: 8.231.157.26, server: abuseip.cc, request: "GET /config.json HTTP/1.1", host: "abuseip.cc" 2026/08/08 06:20:37 [error] 1069336#1069336: *8999 open() "/home/abuseip/public_html/__/firebase/init.json" failed (2: No such file or directory), client: 8.231.157.26, server: abuseip.cc, request: "GET /__/firebase/init.json HTTP/1.1", host: "abuseip.cc" 2026/08/08 06:20:37 [error] 1069336#1069336: *8999 open() "/home/abuseip/public_html/ngsw.json" failed (2: No such file or directory), client: 8.231.157.26, server: abuseip.cc, request: "GET /ngsw.json HTTP/1.1", host: "abuseip.cc" 2026/08/08 06:20:37 [error] 1069336#1069336: *9001 open() "/home/abuseip/pub
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-08 03:32:05
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:31:59.184383 2026] [security2:error] [pid 3506707:tid 3506707] [client 8.231.157.26:35782] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wgs.cc|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wgs.cc"] [uri "/rclone.conf"] [unique_id "anajL6Oq9WX6ehY9o9v8rAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
pixiekat
2026-08-08 02:45:24
(2 weeks ago)
[Sat Aug 08 03:45:24.231336 2026] [security2:error] [pid 365277:tid 365335] [remote 8.231.157.26:574 ...
show more
[Sat Aug 08 03:45:24.231336 2026] [security2:error] [pid 365277:tid 365335] [remote 8.231.157.26:57406] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.28.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.integraldata.cc"] [uri "/rclone.conf"] [unique_id "anaYRHj8V9NqO2IVJ82zRAAAVQo"]
[Sat Aug 08 03:45:24.239470 2026] [security2:error] [pid 365277:tid 365339] [remote 8.231.157.26:57406] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.28.0"] [tag "anomaly-evaluation"
...
show less
Web App Attack
๐ฉ๐ช
todix
2026-08-08 00:17:56
(2 weeks ago)
Web App Attack Exploid from 8.231.157.26
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 23:46:49
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 19:46:42.230777 2026] [security2:error] [pid 2845529:tid 2845529] [client 8.231.157.26:58504] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.qxz.cc|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.qxz.cc"] [uri "/host.key"] [unique_id "anZuYi8f4cx-QUT6lbZX5QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
igerman
2026-08-07 19:32:10
(2 weeks ago)
caddy probes: admin-panel: GET /admin/.env(DROP) | cloud-creds: GET /.aws/config(DROP), GET /.aws/cr ...
show more
caddy probes: admin-panel: GET /admin/.env(DROP) | cloud-creds: GET /.aws/config(DROP), GET /.aws/credentials(DROP) | env-probe: GET /.env(DROP), GET /.env.backup(DROP), GET /.env.bak(DROP), GET /.env.example(DROP), GET /.env.local(DROP), GET /.env.old(DROP), GET /.env.production(DROP), GET /api/.env(DROP), GET /backend/.env(DROP), GET /config/.env(DROP) | git-repo: GET /.git/HEAD(DROP), GET /.git/config(DROP) | web: GET /.git-credentials(DROP), GET /.gitconfig(DROP), GET /.github/workflows/deploy.yml(DROP), GET /.gitlab-ci.yml(DROP), GET /key.json(DROP), GET /secrets.json(DROP), GET /secrets.yml(DROP), GET /service-account.json(DROP), GET /serviceAccountKey.json(DROP), POST /graphql(DROP)
show less
Web App Attack
๐ฉ๐ช
tall1oN
2026-08-07 18:55:42
(2 weeks ago)
8.231.157.26 - - [07/Aug/2026:20:55:42 +0200] "GET /.git-credentials HTTP/2.0" 200 12852 "-" "Mozill ...
show more
8.231.157.26 - - [07/Aug/2026:20:55:42 +0200] "GET /.git-credentials HTTP/2.0" 200 12852 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; MistralAI-User/1.0" "www.demons-gaming.cc"
8.231.157.26 - - [07/Aug/2026:20:55:42 +0200] "GET /.env.example HTTP/2.0" 200 12850 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; MistralAI-User/1.0" "www.demons-gaming.cc"
...
show less
Web App Attack
Port Scan
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-07 18:35:54
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
Octopuce
2026-08-07 17:26:42
(2 weeks ago)
Aggressive web search of vulnerable pages: /.env.local /api/.env /admin/.env /backend/.env /config/. ...
show more
Aggressive web search of vulnerable pages: /.env.local /api/.env /admin/.env /backend/.env /config/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 16:27:10
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 12:27:06.126791 2026] [security2:error] [pid 2125076:tid 2125076] [client 8.231.157.26:55794] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.galvez.cc|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.galvez.cc"] [uri "/rclone.conf"] [unique_id "anYHWi-Ya6jSYu3oiZzUgAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Lazarus
2026-08-07 15:42:29
(2 weeks ago)
HTTP probe.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 14:49:51
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 10:49:47.169230 2026] [security2:error] [pid 2791493:tid 2791493] [client 8.231.157.26:36672] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vanmeter.cc|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vanmeter.cc"] [uri "/privatekey.key"] [unique_id "anXwi99jW6s6jqit5Rl8EwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-08-07 14:20:33
(2 weeks ago)
(modsecurity) srv101 ModSecurity 8.231.157.26 (US/United States/26.157.231.8.bc.googleusercontent.co ...
show more
(modsecurity) srv101 ModSecurity 8.231.157.26 (US/United States/26.157.231.8.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 14:16:05
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.231.157.26 (26.157.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 10:16:00.725083 2026] [security2:error] [pid 14778:tid 14778] [client 8.231.157.26:33940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.spiritcountry.cc|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.spiritcountry.cc"] [uri "/rclone.conf"] [unique_id "anXooF-P5GHEbtBKQH6j0wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack