๐บ๐ธ
oijon.net
2026-10-02 15:20:35
(2 days ago)
[Fri Oct 02 11:20:33.760457 2026] [php:error] [pid 2111533:tid 2111533] [client 8.231.162.80:35756] ...
show more
[Fri Oct 02 11:20:33.760457 2026] [php:error] [pid 2111533:tid 2111533] [client 8.231.162.80:35756] script '/var/www/oijon/calendar/html/phpinfo.php' not found or unable to stat
[Fri Oct 02 11:20:33.823773 2026] [php:error] [pid 2111542:tid 2111542] [client 8.231.162.80:35748] script '/var/www/oijon/calendar/html/info.php' not found or unable to stat
[Fri Oct 02 11:20:34.122370 2026] [php:error] [pid 2111538:tid 2111538] [client 8.231.162.80:35832] script '/var/www/oijon/calendar/html/app_dev.php' not found or unable to stat
[Fri Oct 02 11:20:34.205288 2026] [php:error] [pid 2111538:tid 2111538] [client 8.231.162.80:35832] script '/var/www/oijon/calendar/html/app_dev.php' not found or unable to stat
[Fri Oct 02 11:20:34.689924 2026] [php:error] [pid 2111538:tid 2111538] [client 8.231.162.80:35832] script '/var/www/oijon/calendar/html/pi.php' not found or unable to stat
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:50:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:49:56.075521 2026] [security2:error] [pid 12904:tid 12904] [client 8.231.162.80:52234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.globalpackets.net"] [uri "/.env.js"] [unique_id "ar_ElAjs7OmaTF0PfHC6EQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:26:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:26:11.663959 2026] [security2:error] [pid 18890:tid 18890] [client 8.231.162.80:45104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thinksite.net"] [uri "/dist../.env"] [unique_id "ar-_A8qqbZ-oCbp3mdcudQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-02 14:05:42
(2 days ago)
8.231.162.80 - - [02/Oct/2026:16:05:40 +0200] "GET /%2e%2e/.env HTTP/2.0" 400 325 "-" "Mozilla/5.0 ( ...
show more
8.231.162.80 - - [02/Oct/2026:16:05:40 +0200] "GET /%2e%2e/.env HTTP/2.0" 400 325 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
8.231.162.80 - - [02/Oct/2026:16:05:40 +0200] "GET /media../.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
8.231.162.80 - - [02/Oct/2026:16:05:40 +0200] "GET /admin%2F.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
8.231.162.80 - - [02/Oct/2026:16:05:40 +0200] "GET /files../.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
8.231.162.80 - - [02/Oct/2026:16:05:40 +0200] "GET /api%2F.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])"
8.231.162.80 - - [02/Oct/2026:16:05:40 +0200] "GET /assets../.env HTTP/2.0" 403 298 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML,
show less
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-10-02 14:03:41
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 13:51:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:51:17.492947 2026] [security2:error] [pid 5207:tid 5299] [client 8.231.162.80:36626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pinnaclemgmt.net"] [uri "/.htpasswd"] [unique_id "ar-21YFwNzsvLTRdN4SsDwAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:29:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:29:31.250993 2026] [security2:error] [pid 26462:tid 26462] [client 8.231.162.80:38150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kelting.net"] [uri "/.htpasswd"] [unique_id "ar-xuwCjSM84B5cCbEtCtwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
stinpriza
2026-10-02 13:16:49
(2 days ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:47:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:47:35.599282 2026] [security2:error] [pid 28675:tid 28675] [client 8.231.162.80:57362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infodevman.net"] [uri "/dist../.env"] [unique_id "ar-n5zRzWMF7NCwuk7F3bgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:19:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:19:49.094728 2026] [security2:error] [pid 7459:tid 7459] [client 8.231.162.80:42794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dinsbach.net"] [uri "/.env.js"] [unique_id "ar-hZeRKLq4D5S5mCbToJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-02 12:07:09
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php-cgi
Query: ?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input
Timestamp: 2026-10-02T10:04:34Z
Ray ID: a442e239deef5050
UA: Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 11:42:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:42:07.926778 2026] [security2:error] [pid 31639:tid 31639] [client 8.231.162.80:33110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarahpeebles.net"] [uri "/api/fs/read"] [unique_id "ar-Yj9v_fzyoFYrx3gGHXgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-02 11:39:51
(2 days ago)
804 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
jfz-abuse
2026-10-02 11:04:52
(2 days ago)
fail2ban: apache-php-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:59:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.162.80 (80.162.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:59:20.101093 2026] [security2:error] [pid 20924:tid 20924] [client 8.231.162.80:59566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scothorn.net"] [uri "/js../.env"] [unique_id "ar-OiA0E_1oePk9Wh41_MQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack