๐ฆ๐บ
aranguren.org
2026-06-14 04:05:53
(1 hour ago)
85.121.48.227 - - [14/Jun/2026:14:05:52 +1000] "GET /secrets.yml HTTP/1.1" 404 985 "-" "Mozilla/5.0 ...
show more
85.121.48.227 - - [14/Jun/2026:14:05:52 +1000] "GET /secrets.yml HTTP/1.1" 404 985 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
85.121.48.227 - - [14/Jun/2026:14:05:52 +1000] "GET /application.yml HTTP/1.1" 404 985 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot"
85.121.48.227 - - [14/Jun/2026:14:05:52 +1000] "GET /.aws/credentials HTTP/1.1" 404 985 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
85.121.48.227 - - [14/Jun/2026:14:05:52 +1000] "GET /secrets.json HTTP/1.1" 404 985 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
85.121.48.227 - - [14/Jun/2026:14:05:52 +1000] "GET /.env.example HTTP/1.1" 404 985 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot"
85.121.48.227 - - [14/Jun/2026:14:05:52 +1000] "GET /google-services.json HTTP/1.1" 404
...
show less
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-06-14 01:47:31
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ธ๐ช
KIDOS
2026-06-13 23:01:19
(6 hours ago)
CrowdSec detected malicious activity
DDoS Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-13 22:06:58
(7 hours ago)
Auto-ban: >3000 req/min op 2026-06-13
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-13 20:18:50
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 16:18:44.100375 2026] [security2:error] [pid 9180:tid 9180] [client 85.121.48.227:47126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "princessnapkins.com"] [uri "/.env.example"] [unique_id "ai27JHutkBL0HNdCBf5j2QAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 19:59:00
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 15:58:54.137978 2026] [security2:error] [pid 31815:tid 31823] [client 85.121.48.227:45818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "princesscastlebunkbed.davidholls.com"] [uri "/.env"] [unique_id "ai22fp_5-QARx_a3IC7wqQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-13 18:47:47
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 13:09:23
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 09:09:19.002906 2026] [security2:error] [pid 5144:tid 5144] [client 85.121.48.227:58160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "priceimprovement.iainrealtor.com"] [uri "/.env.example"] [unique_id "ai1Wf_1K3NXOjD2bdgJRQAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 12:20:34
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:20:29.150787 2026] [security2:error] [pid 13478:tid 13478] [client 85.121.48.227:35368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prezence.com"] [uri "/.env"] [unique_id "ai1LDf23ug5JcpviYij7EgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-13 11:15:07
(18 hours ago)
Web App Attack
๐จ๐ญ
leo1305
2026-06-13 10:44:00
(19 hours ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 04:51:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.48.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 00:51:16.856623 2026] [security2:error] [pid 21508:tid 21508] [client 85.121.48.227:45646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grayhost.net"] [uri "/.env.example"] [unique_id "aizhxJ9-l-CpF9IyqvziogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-13 01:43:25
(1 day ago)
118 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-06-13 01:35:33
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฎ๐น
Inartis
2026-06-13 01:00:49
(1 day ago)
85.121.48.227 - - [13/Jun/2026:03:00:48 +0200] "GET /.env.example HTTP/1.1" 500 195 "-" "Mozilla/5.0 ...
show more
85.121.48.227 - - [13/Jun/2026:03:00:48 +0200] "GET /.env.example HTTP/1.1" 500 195 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack