๐บ๐ธ
TPI-Abuse
2026-06-02 09:56:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:55:59.035963 2026] [security2:error] [pid 25877:tid 25877] [client 85.121.127.115:38842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1derfulwaysrv.com"] [uri "/.git/config"] [unique_id "ah6or0rOQDL6bjmRJYkeTQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 09:25:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:25:52.591917 2026] [security2:error] [pid 21298:tid 21298] [client 85.121.127.115:49388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1cdn.com"] [uri "/.git/config"] [unique_id "ah6hoMzpjL1nMstxexCDgQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-02 08:38:25
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
MPL
2026-06-02 07:04:55
(1 day ago)
tcp ports: 443,80 (6 or more attempts)
Port Scan
๐ซ๐ท
polido
2026-06-02 07:04:11
(1 day ago)
Unauthorized connection attempt to port 443 from 85.121.127.115
Port Scan
๐ซ๐ท
SpaceHost-Server
2026-06-01 22:36:23
(2 days ago)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-01 14:35:54
(2 days ago)
543 requests with url.path *.env
312 requests with url.path *config.json
194 requests with url.pa ...
show more
543 requests with url.path *.env
312 requests with url.path *config.json
194 requests with url.path *secrets.yml
147 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
Blexyel
2026-06-01 12:05:16
(2 days ago)
85.121.127.115 - - [01/Jun/2026:14:05:15 +0200] "GET /.git/config HTTP/1.1" 200 2116 "-" "Mozilla/5. ...
show more
85.121.127.115 - - [01/Jun/2026:14:05:15 +0200] "GET /.git/config HTTP/1.1" 200 2116 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
infra-monitor
2026-06-01 12:00:05
(2 days ago)
Automated ban via infra-monitor: suspicious-probe
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-01 11:31:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 07:30:59.747827 2026] [security2:error] [pid 7097:tid 7153] [client 85.121.127.115:33112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sh2.lol"] [uri "/.git/config"] [unique_id "ah1tcyU_mlkdcuOjqE598QAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-06-01 11:10:42
(2 days ago)
85.121.127.115 - - [01/Jun/2026:13:10:42 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
85.121.127.115 - - [01/Jun/2026:13:10:42 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 10:53:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 06:53:02.019808 2026] [security2:error] [pid 23619:tid 23619] [client 85.121.127.115:38780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4md.lol"] [uri "/.git/config"] [unique_id "ah1kjq_R_ENoyJPHHus3MgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-06-01 10:37:11
(2 days ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
macrob
2026-06-01 10:22:32
(2 days ago)
2026/06/01 10:22:30 [error] 478276#478276: *272570007 access forbidden by rule, client: 85.121.127.1 ...
show more
2026/06/01 10:22:30 [error] 478276#478276: *272570007 access forbidden by rule, client: 85.121.127.115, server: bin.partners, request: "GET /.git/config HTTP/2.0", host: "bin.partners"
2026/06/01 10:22:30 [error] 478276#478276: *272570021 access forbidden by rule, client: 85.121.127.115, server: bin.partners, request: "GET /vault.env HTTP/2.0", host: "bin.partners"
2026/06/01 10:22:30 [error] 478274#478274: *272570024 access forbidden by rule, client: 85.121.127.115, server: bin.partners, request: "GET /.aws/credentials HTTP/2.0", host: "bin.partners"
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-06-01 09:18:05
(2 days ago)
Web attack/malicious scanning detected
Web App Attack