πΊπΈ
TPI-Abuse
2026-05-31 04:23:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 00:23:48.007734 2026] [security2:error] [pid 31594:tid 31594] [client 85.121.127.81:56410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honkouji.ichi51e.net"] [uri "/.git/config"] [unique_id "ahu31Mhk3wnP4fledmrkuAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 03:45:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 23:44:56.818599 2026] [security2:error] [pid 13257:tid 13257] [client 85.121.127.81:37842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honeybeeplace.com"] [uri "/.git/config"] [unique_id "ahuuuAWW5kk0YhcOMZHemgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
poundawebsiteltd
2026-05-31 03:34:43
(3 days ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:80 85.121.127.81 - - [31/May/2026:04 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:80 85.121.127.81 - - [31/May/2026:04:34:41 +0100] GET /application.yml HTTP/1.1 404 154 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://[REDACTED_DOMAIN]/bot
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 03:27:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 23:27:43.188277 2026] [security2:error] [pid 6903:tid 6903] [client 85.121.127.81:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hondabvi.com"] [uri "/.git/config"] [unique_id "ahuqrxocc4Uq0xDe4dKCxQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
Bots.go.to.hell
2026-05-31 02:04:24
(3 days ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
π¬π§
andypiper
2026-05-31 01:01:56
(3 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 00:13:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.127.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.127.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 20:13:27.951086 2026] [security2:error] [pid 11962:tid 11962] [client 85.121.127.81:41766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homebuilt.michaelsabbey.org"] [uri "/.git/config"] [unique_id "aht9J8uo8bc0FCPvO3Gp5gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hary74656
2026-05-30 22:58:55
(4 days ago)
[Sun May 31 00:58:50.519762 2026] [security2:error] [pid 373240:tid 373269] [remote 85.121.127.81:34 ...
show more
[Sun May 31 00:58:50.519762 2026] [security2:error] [pid 373240:tid 373269] [remote 85.121.127.81:34932] [client 85.121.127.81] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "weavernet.at"] [uri "/.aws/credentials"] [unique_id "ahtrqosnIIfDBnmALWK3jwABbQI"]
[Sun May 31 00:58:50.625526 2026] [security2:error] [pid 373240:tid 373274] [remote 85.121.127.81:34932] [client 85.121.127.81] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.git/" a
...
show less
Web App Attack
π©πͺ
gadix
2026-05-30 22:13:51
(4 days ago)
[31/May/2026:00:13:48.962748 +0200] ahthHC9jgsUlxv_zzrjCZAAAAFY 85.121.127.81 57558 127.0.0.1 7080
[ ...
show more
[31/May/2026:00:13:48.962748 +0200] ahthHC9jgsUlxv_zzrjCZAAAAFY 85.121.127.81 57558 127.0.0.1 7080
[31/May/2026:00:13:49.513920 +0200] ahthHb93bQnXYEK6gC5zVQAAABc 85.121.127.81 57592 127.0.0.1 7080
[31/May/2026:00:13:50.968202 +0200] ahthHi9jgsUlxv_zzrjCZwAAAEM 85.121.127.81 57616 127.0.0.1 7080
...
show less
Web App Attack
Anonymous
2026-05-30 22:09:34
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π³π±
homeshowdomain.nl
2026-05-30 21:59:22
(4 days ago)
Auto-ban: >3000 req/min op 2026-05-30
Web App Attack
SSH
Hacking
πΈπͺ
nekopavel
2026-05-30 21:39:53
(4 days ago)
85.121.127.81 - - [30/May/2026:23:39:50 +0200]"GET /.aws/credentials HTTP/2.0" 200 1482"-" pavel.gg ...
show more
85.121.127.81 - - [30/May/2026:23:39:50 +0200]"GET /.aws/credentials HTTP/2.0" 200 1482"-" pavel.gg "Mozilla/5.0 (compatible; Bytespider; [email protected] )""0.000" "-""The Hague" "NL"
85.121.127.81 - - [30/May/2026:23:39:50 +0200]"GET /vault.env HTTP/2.0" 200 1482"-" pavel.gg "Mozilla/5.0 (compatible; Bytespider; [email protected] )""0.000" "-""The Hague" "NL"
85.121.127.81 - - [30/May/2026:23:39:50 +0200]"GET /.git/config HTTP/2.0" 200 1482"-" pavel.gg "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user""0.000" "-""The Hague" "NL"
...
show less
Hacking
Bad Web Bot
Web App Attack
π©πͺ
on-com
2026-05-30 21:34:03
(4 days ago)
URL scan
Brute-Force
Web App Attack
π΅π±
itsvic.dev
2026-05-30 20:38:39
(4 days ago)
85.121.127.81 - - [30/May/2026:20:38:25 +0000] "GET /.env HTTP/2.0" 404 14 "-" "Mozilla/5.0 (compati ...
show more
85.121.127.81 - - [30/May/2026:20:38:25 +0000] "GET /.env HTTP/2.0" 404 14 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
85.121.127.81 - - [30/May/2026:20:38:38 +0000] "GET /wp-json/wp/v2/ HTTP/2.0" 404 14 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
85.121.127.81 - - [30/May/2026:20:38:38 +0000] "GET /wp-json/ HTTP/2.0" 404 14 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
...
show less
Brute-Force
Web App Attack
πΊπΈ
Charlesiv
2026-05-30 20:01:02
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 9009 (M247 Europe SRL)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 9009 (M247 Europe SRL)
Protocol: HTTP/2 (GET method)
Endpoint: /_next/static/buildManifest.js
Timestamp: 2026-05-30T19:35:33Z
Ray ID: a0402ec15e2ba00a
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 DingTalk(2.7.10) com.laiwang.DingTalk/35900215 Channel/201200 language/zh-Hans-CN
show less
Bad Web Bot