🇺🇸
TPI-Abuse
2026-09-06 03:50:17
(24 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:12.282625 2026] [security2:error] [pid 14049:tid 14049] [client 104.155.34.239:42160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gacstoday.com"] [uri "/.env.prod"] [unique_id "apzi9J9kN9aqpXsIkGLDqAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 03:38:16
(36 minutes ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 104.155.34.239 (BE/Belgium/239.34.155 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 104.155.34.239 (BE/Belgium/239.34.155.104.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 03:34:18
(40 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
Petros Stefanakis
2026-09-06 03:01:56
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 104.155.34.239 (BE/Belgium/239.34.155.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.155.34.239 (BE/Belgium/239.34.155.104.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 03:01:53
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:47.792978 2026] [security2:error] [pid 2074:tid 2074] [client 104.155.34.239:57712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hollorancompanies.com"] [uri "/.env.dev"] [unique_id "apzXm_jQpCm10JQiQMTJfAAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:34:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:34:42.609255 2026] [security2:error] [pid 27281:tid 27281] [client 104.155.34.239:47276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flyingcardcompany.com"] [uri "/wp-config.php.swp"] [unique_id "apzRQvbV8jKIe1OXEtjx0gAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 01:39:10
(2 hours ago)
Domain : yourmastermindgroup.com
Rule : hack
2026-09-06 01:38:08 ***hidden-privacy*** GET /wp-config ...
show more
Domain : yourmastermindgroup.com
Rule : hack
2026-09-06 01:38:08 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 104.155.34.239 HTTP/1.1 crusader-worker/1.0 - yourmastermindgroup.com 403 0 0 1360 112 217 - -
show less
Hacking
SQL Injection
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 01:37:03
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:36:56.231423 2026] [security2:error] [pid 3505775:tid 3505866] [client 104.155.34.239:36232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "miltonthepuppy.com"] [uri "/.env.example"] [unique_id "apzDuL8ERl7gWgWoAPLwAAAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
AutosOnShow
2026-09-06 01:30:07
(2 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-09-06 01:29:19.256 |
Web App Attack
🇦🇺
AWW-Admin
2026-09-06 00:41:33
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 104.155.34.239 (BE/Belgium/239.34.155.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.155.34.239 (BE/Belgium/239.34.155.104.bc.googleusercontent.com)
show less
SQL Injection
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:39:04
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:36:14
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:36:08.337946 2026] [security2:error] [pid 8128:tid 8128] [client 104.155.34.239:33178] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||avalonestates.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "avalonestates.org"] [uri "/dump.sql"] [unique_id "apy1eB_U_Jayl1rHS4vbXQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Dennis
2026-09-06 00:31:00
(3 hours ago)
104.155.34.239 has been banned for triggering http-sensitive-files (5 events over 8.469495ms).
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:27:32
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.34.239 (239.34.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:27:26.674911 2026] [security2:error] [pid 14092:tid 14092] [client 104.155.34.239:48750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.leonardodecaprio.com"] [uri "/.htaccess"] [unique_id "apylXg6sfRiGdhNsFuR0XgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:04:32
(5 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 104.155.34.239 (BE/Belgium/239.34.155.104.bc ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 104.155.34.239 (BE/Belgium/239.34.155.104.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.155.34.239 - - [06/Sep/2026:01:04:29 +0200] "GET /.env.dev HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
104.155.34.239 - - [06/Sep/2026:01:04:29 +0200] "GET /.env.local HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
104.155.34.239 - - [06/Sep/2026:01:04:29 +0200] "GET /.env.old HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan