๐บ๐ธ
TPI-Abuse
2026-06-03 13:39:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 09:39:18.568948 2026] [security2:error] [pid 802:tid 802] [client 85.121.127.121:43298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "providencesilverco.com"] [uri "/.git/config"] [unique_id "aiAuhtcPtx6TxLeeI5kkpAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 07:57:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 03:57:21.415471 2026] [security2:error] [pid 10611:tid 10611] [client 85.121.127.121:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaitanyaconsult.in"] [uri "/.git/config"] [unique_id "ah_eYfT8XJx1ly8dwNye_gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 06:52:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:52:48.088378 2026] [security2:error] [pid 19912:tid 19912] [client 85.121.127.121:57948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markallan.com"] [uri "/.git/config"] [unique_id "ah_PQBzadTwaOyysPKHxFgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 06:19:45
(2 days ago)
85.121.127.121 - - [03/Jun/2026:01:19:39 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "meta-exter ...
show more
85.121.127.121 - - [03/Jun/2026:01:19:39 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)" 85.121.127.121
85.121.127.121 - - [03/Jun/2026:01:19:40 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot" 85.121.127.121
85.121.127.121 - - [03/Jun/2026:01:19:41 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " 85.121.127.121
85.121.127.121 - - [03/Jun/2026:01:19:41 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "anthropic-ai" 85.121.127.121
85.121.127.121 - - [03/Jun/2026:01:19:41 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 85.121.127.121
85.121.127.121 - - [03/Jun/2026:01:19:43 -0500] "GET /.env.devel
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-03 06:09:43
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 04:57:18
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 00:57:11.969295 2026] [security2:error] [pid 31229:tid 31229] [client 85.121.127.121:45222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kipdollar.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kipdollar.com"] [uri "/storage/logs/laravel.log"] [unique_id "ah-0J7X7ChAavoeLXOznPgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-03 04:30:04
(2 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 04:12:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 00:12:39.690046 2026] [security2:error] [pid 7985:tid 7985] [client 85.121.127.121:56248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zackfranz.com"] [uri "/.git/config"] [unique_id "ah-ptxBAE3kLtrgTWSc07gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 03:59:03
(2 days ago)
Bot / scanning and/or hacking attempts: GET /manifest.json HTTP/1.1, GET /webpack-stats.json HTTP/1. ...
show more
Bot / scanning and/or hacking attempts: GET /manifest.json HTTP/1.1, GET /webpack-stats.json HTTP/1.1, GET /asset-manifest.json HTTP/1.1, GET /config.json HTTP/1.1, GET /.git/config HTTP/1.1, GET /secrets.json HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-06-03 03:13:23
(2 days ago)
85.121.127.121 - - [03/Jun/2026:05:13:03 +0200] "GET /secrets.yml HTTP/1.1" 404 29753
85.121.127.121 ...
show more
85.121.127.121 - - [03/Jun/2026:05:13:03 +0200] "GET /secrets.yml HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:03 +0200] "GET /application.yml HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:03 +0200] "GET /secrets.json HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:09 +0200] "GET /application.properties HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:09 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:09 +0200] "GET /config/application.properties HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:13 +0200] "GET /config/secrets.yml HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:20 +0200] "GET /v1/graphql HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:20 +0200] "GET /__/firebase/init.json HTTP/1.1" 404 29753
85.121.127.121 - - [03/Jun/2026:05:13:20 +0200] "GET /config.json HTTP/1.1" 404 29753
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-06-03 02:47:27
(2 days ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 02:15:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 22:15:30.565042 2026] [security2:error] [pid 13564:tid 13564] [client 85.121.127.121:33000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joescherzi.com"] [uri "/.git/config"] [unique_id "ah-OQlnM_ZCuZtGduTJhWwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-03 01:22:32
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
andypiper
2026-06-03 01:02:56
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 00:52:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 20:52:10.278893 2026] [security2:error] [pid 21284:tid 21284] [client 85.121.127.121:36108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boens.org"] [uri "/.git/config"] [unique_id "ah96uoqQxFZxx02tq_4ucgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack