🇬🇧
consul.to
2026-09-08 02:31:23
(20 minutes ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:20:42
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:20:36.298919 2026] [security2:error] [pid 28841:tid 28841] [client 104.155.205.211:4722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.twinls.com"] [uri "/@fs/src/.env"] [unique_id "ap9w9G6zexS6rbTWnYWEEAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-08 02:04:42
(47 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:03:12
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:03:09.515763 2026] [security2:error] [pid 31176:tid 31176] [client 104.155.205.211:10534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.scsurfside.net"] [uri "/@fs/.env"] [unique_id "ap9s3Q-6SANUvIDce9eOxAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:38:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:38:04.517621 2026] [security2:error] [pid 5258:tid 5258] [client 104.155.205.211:42852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.digi-estudio.com"] [uri "/@fs/.env"] [unique_id "ap9m_OSr36gr9_8Wgv_emAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 01:33:23
(1 hour ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-196)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 01:21:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:21:47.106195 2026] [security2:error] [pid 1232522:tid 1232535] [client 104.155.205.211:51364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furball.m3sxa.com"] [uri "/@fs/src/.env"] [unique_id "ap9jK5UCARSMRgztTofSpAAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 01:17:06
(1 hour ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 01:03:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.205.211 (211.205.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:03:46.615466 2026] [security2:error] [pid 24921:tid 24921] [client 104.155.205.211:18718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.commercialphotostudiorental.com"] [uri "/@fs/root/.env"] [unique_id "ap9e8iYkzyf7ZboGPBqKyQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 00:27:13
(2 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-08 00:15:40
(2 hours ago)
20 attempts against mh-misbehave-ban on hail
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-08 00:12:08
(2 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇫🇷
masterguru
2026-09-07 23:59:42
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-07 23:59:12
(2 hours ago)
104.155.205.211 - - [08/Sep/2026:01:59:12 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 124 "-" "Moz ...
show more
104.155.205.211 - - [08/Sep/2026:01:59:12 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
104.155.205.211 - - [08/Sep/2026:01:59:12 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
104.155.205.211 - - [08/Sep/2026:01:59:12 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Chrome/109.0.359.98 Mobile Safari/537.36"
104.155.205.211 - - [08/Sep/2026:01:59:12 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
104.155.205.211 - - [08/Sep/2026:01:59:12 +0200] "GET /@fs/../.env?ra
...
show less
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-07 23:57:52
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack