Anonymous
2026-06-29 08:46:12
(6 hours ago)
Bot / seems abusive / Apache connections: 20
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
nasset
2026-06-29 08:30:11
(7 hours ago)
94.176.161.67 - - [29/Jun/2026:01:30:11 -0700] "GET /gcp-credentials.json HTTP/1.1" 403 584 "-" "ant ...
show more
94.176.161.67 - - [29/Jun/2026:01:30:11 -0700] "GET /gcp-credentials.json HTTP/1.1" 403 584 "-" "anthropic-ai"
94.176.161.67 - - [29/Jun/2026:01:30:11 -0700] "GET /google-credentials.json HTTP/1.1" 403 584 "-" "anthropic-ai"
94.176.161.67 - - [29/Jun/2026:01:30:11 -0700] "GET /sa.json HTTP/1.1" 403 584 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
94.176.161.67 - - [29/Jun/2026:01:30:11 -0700] "GET /key.json HTTP/1.1" 403 584 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
94.176.161.67 - - [29/Jun/2026:01:30:11 -0700] "GET /.docker/config.json HTTP/1.1" 403 584 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-06-29 07:59:39
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-06-29 05:14:54
(10 hours ago)
26 attacks on config grabbing URLs (type 2), VC URLs, password grabbing URLs, env grabbing URLs:
GET ...
show more
26 attacks on config grabbing URLs (type 2), VC URLs, password grabbing URLs, env grabbing URLs:
GET /app-config.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /public/.env HTTP/1.1
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-29 04:55:35
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.176.161.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.176.161.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 00:55:28.683693 2026] [security2:error] [pid 24841:tid 24841] [client 94.176.161.67:35730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tucek.org"] [uri "/.git/config"] [unique_id "akH6wNYqFw3ykPAFnJeeLAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-29 03:37:59
(11 hours ago)
94.176.161.67 - - [29/Jun/2026:06:37:59 +0300] "GET /vault.env HTTP/1.1" 404 4615 "-" "Mozilla/5.0 ( ...
show more
94.176.161.67 - - [29/Jun/2026:06:37:59 +0300] "GET /vault.env HTTP/1.1" 404 4615 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
...
show less
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-28 22:30:27
(17 hours ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-28 22:01:07
(17 hours ago)
Auto-ban: >3000 req/min op 2026-06-28
Web App Attack
SSH
Hacking
Anonymous
2026-06-28 19:56:20
(19 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-06-28 16:32:02
(23 hours ago)
2026/06/28 17:32:00 [error] 1094875#1094875: *1795706 access forbidden by rule, client: 94.176.161.6 ...
show more
2026/06/28 17:32:00 [error] 1094875#1094875: *1795706 access forbidden by rule, client: 94.176.161.67, server: gwynethllewelyn.net, request: "GET /.env HTTP/2.0", host: "gwynethllewelyn.net"
94.176.161.67 - - [28/Jun/2026:17:32:00 +0100] "GET /.env HTTP/2.0" 403 1048 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
2026/06/28 17:32:01 [error] 1094874#1094874: *1795711 access forbidden by rule, client: 94.176.161.67, server: gwynethllewelyn.net, request: "GET /app/.env HTTP/2.0", host: "gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-06-28 14:03:53
(1 day ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-06-28 12:53:13
(1 day ago)
94.176.161.67 - - [28/Jun/2026:15:53:10 +0300] "GET /.env HTTP/1.1" 404 650 "-" "Mozilla/5.0 AppleWe ...
show more
94.176.161.67 - - [28/Jun/2026:15:53:10 +0300] "GET /.env HTTP/1.1" 404 650 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot"
94.176.161.67 - - [28/Jun/2026:15:53:12 +0300] "GET /config.env HTTP/1.1" 404 650 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-28 09:45:40
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-28 09:06:30
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 07:26:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 94.176.161.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.176.161.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 03:26:15.992063 2026] [security2:error] [pid 26929:tid 27073] [client 94.176.161.67:45616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liamkiriadcompany.brucejoell.com"] [uri "/.git/config"] [unique_id "akDMl4iuuSst5nHMRwqbogAAAow"]
show less
Brute-Force
Bad Web Bot
Web App Attack