Anonymous
2026-06-01 08:47:47
(5 days ago)
Blocked: Reason='Suspicious traffic score=70 (review-based detection)'; Requests=56
Hacking
π¬π§
openstrike.co.uk
2026-06-01 05:13:38
(5 days ago)
8 attacks on config grabbing URLs (type 2), password grabbing URLs, VC URLs:
GET /settings.json HTTP ...
show more
8 attacks on config grabbing URLs (type 2), password grabbing URLs, VC URLs:
GET /settings.json HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /.git/config HTTP/1.1
show less
Hacking
πΊπΈ
TPI-Abuse
2026-05-31 19:09:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 15:09:46.830287 2026] [security2:error] [pid 12792:tid 12792] [client 85.121.127.76:35930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fanarch.xyz"] [uri "/.git/config"] [unique_id "ahyHeqch_DHF5kKKGZWQlAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 18:45:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 14:45:47.732011 2026] [security2:error] [pid 1853:tid 1853] [client 85.121.127.76:55808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zombiekillabob.com"] [uri "/.git/config"] [unique_id "ahyB27Ckb3z3LrlYyWvgBwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-05-31 18:07:42
(5 days ago)
Excessive 404/403 errors
Brute-Force
π©πͺ
Hary74656
2026-05-31 17:34:50
(5 days ago)
[Sun May 31 19:32:52.870627 2026] [security2:error] [pid 728269:tid 728349] [remote 85.121.127.76:49 ...
show more
[Sun May 31 19:32:52.870627 2026] [security2:error] [pid 728269:tid 728349] [remote 85.121.127.76:49970] [client 85.121.127.76] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "fallback.weavernet.at"] [uri "/.aws/credentials"] [unique_id "ahxwxC6H8D1fKyexjKXwgwAC0gI"], referer: http://fallback.weavernet.at/.aws/credentials
[Sun May 31 19:32:58.078846 2026] [security2:error] [pid 728269:tid 728355] [remote 85.121.127.76:49970] [client 85.121.127.76] ModSecurity:
...
show less
Web App Attack
π©πͺ
Nevermind
2026-05-31 17:25:34
(5 days ago)
85.121.127.76 - - [31/May/2026:19:25:21 +0200] "GET /.aws/credentials HTTP/1.1" 404 4183 "-" "CCBot/ ...
show more
85.121.127.76 - - [31/May/2026:19:25:21 +0200] "GET /.aws/credentials HTTP/1.1" 404 4183 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
85.121.127.76 - - [31/May/2026:19:25:21 +0200] "GET /secrets.json HTTP/1.1" 404 4183 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
85.121.127.76 - - [31/May/2026:19:25:22 +0200] "GET /.git/config HTTP/1.1" 403 4186 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
85.121.127.76 - - [31/May/2026:19:25:34 +0200] "GET /.env HTTP/1.1" 403 4186 "-" "Mozilla/5.0 (compatible; Claude-Web/1.0; +https://www.anthropic.com)"
...
show less
Web App Attack
πΊπΈ
ambor
2026-05-31 16:56:32
(5 days ago)
Honeypot access: Git configuration file access attempt. Path: /.git/config
Web App Attack
π©πͺ
bescared
2026-05-31 16:08:21
(5 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
π©πͺ
ger-stg-sifi1
2026-05-31 15:53:43
(5 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π«π·
masterguru
2026-05-31 15:28:37
(5 days ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 15:28:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 11:28:19.816720 2026] [security2:error] [pid 15077:tid 15077] [client 85.121.127.76:55138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fagerbergfamily.net"] [uri "/.git/config"] [unique_id "ahxTkyIie5svfqc4AEIGFQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 15:06:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 11:06:10.754840 2026] [security2:error] [pid 6185:tid 6185] [client 85.121.127.76:52096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fadcometal.com"] [uri "/.git/config"] [unique_id "ahxOYl4SHc5FrKETuRiHuwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
elcruzado.es
2026-05-31 14:50:49
(5 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 85.121.127.76 (-)
Bad Web Bot
π¬π§
consul.to
2026-05-31 14:50:43
(5 days ago)
Web attack/malicious scanning detected
Web App Attack