π§πΎ
lns.bz
2026-10-01 17:56:11
(1 day ago)
Too many 404 requests [BY]
Web App Attack
π³π±
e.fierstra
2026-10-01 17:45:04
(1 day ago)
excessive HTTP 404 errors
Bad Web Bot
π©πͺ
LRob
2026-10-01 15:58:11
(1 day ago)
Secret file probe | method: GET | path: /media../.env, /static//.env, /static../.env (+8 more) | ua: ...
show more
Secret file probe | method: GET | path: /media../.env, /static//.env, /static../.env (+8 more) | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot), Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/), Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/) (+8 more)
show less
Hacking
Web App Attack
π¬π§
Aetherweb Ark
2026-10-01 14:11:14
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 8.234.199.157 (US/United States/157.199.234.8.b ...
show more
(mod_security) mod_security (id:949110) triggered by 8.234.199.157 (US/United States/157.199.234.8.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
πΈπͺ
eagle
2026-10-01 13:56:21
(1 day ago)
8.234.199.157 - - [01/Oct/2026:13:56:21 +0000] "POST / HTTP/2.0" 401 37 "-" "Mozilla/5.0 (compatible ...
show more
8.234.199.157 - - [01/Oct/2026:13:56:21 +0000] "POST / HTTP/2.0" 401 37 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 13:14:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.199.157 (157.199.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.199.157 (157.199.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:14:44.359121 2026] [security2:error] [pid 32183:tid 32183] [client 8.234.199.157:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "email.thectegroup.net"] [uri "/.env.js"] [unique_id "ar5cxNoKWWFwUNrk8wxLOgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
updown.io
2026-10-01 12:55:52
(1 day ago)
{"level":"info","ts":1790859349.7536697,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790859349.7536697,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"8.234.199.157","remote_port":"41042","client_ip":"8.234.199.157","proto":"HTTP/2.0","method":"GET","host":"status.testmail.app","uri":"/dist/manifest.json","headers":{"Sec-Fetch-Dest":["document"],"Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Site":["none"],"Sec-Ch-Ua-Platform":["\"Windows\""],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Fetch-Mode":["navigate"],"X-Nextjs-Data":["1"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Fetch-User":["?1"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Priority":["u=0, i"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middle
...
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 12:47:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.199.157 (157.199.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.199.157 (157.199.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:47:47.999070 2026] [security2:error] [pid 23833:tid 23833] [client 8.234.199.157:46338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jbaydeliveries.com"] [uri "/.git/HEAD"] [unique_id "ar5Wc8XNt6u_KssTi0JrZgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:22:31
(1 day ago)
Portscan: TCP/8080 (3x), TCP/8443 (3x)
Port Scan
π¨π
zynex
2026-10-01 12:12:48
(1 day ago)
URL Probing: /static/app/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 12:11:21
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 8.234.199.157 (157.199.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 8.234.199.157 (157.199.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:11:15.416703 2026] [security2:error] [pid 8356:tid 8356] [client 8.234.199.157:45398] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "old.pathpointsandbox.click"] [uri "/js../.env"] [unique_id "ar5N41Qk4p9nTFou9giEiAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
bohl-aiG5aef
2026-10-01 12:08:38
(1 day ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
Anonymous
2026-10-01 10:49:11
(1 day ago)
Web scanner: GET /js../.env
Web App Attack
Hacking
π³π±
Site.eu
2026-10-01 10:39:51
(1 day ago)
Excessive multi-domain requests
Brute-Force
π¬π§
noise.agency
2026-10-01 10:37:58
(1 day ago)
8.234.199.157 (US/United States/157.199.234.8.bc.googleusercontent.com), more than 10 Apache 403 hit ...
show more
8.234.199.157 (US/United States/157.199.234.8.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking