🇧🇪
taivas.nl
2026-09-06 04:32:49
(28 minutes ago)
Many_bad_calls
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:24.432320 2026] [security2:error] [pid 23477:tid 23477] [client 104.196.124.64:33084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.whlr.net"] [uri "/.env.local"] [unique_id "apzjeCju9Yd_iDqWAufGvgAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-06 03:19:22
(1 hour ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
🇫🇷
✨
2026-09-06 03:06:16
(1 hour ago)
Domain : MailEnable WebMail
Rule : config
2026-09-06 03:03:29 ***hidden-privacy*** GET /wp-config.ph ...
show more
Domain : MailEnable WebMail
Rule : config
2026-09-06 03:03:29 ***hidden-privacy*** GET /wp-config.php~ - 443 - 104.196.124.64 crusader-worker/1.0 - 404 0 2 1569 105 103 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:58:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:45.154760 2026] [security2:error] [pid 3660588:tid 3660588] [client 104.196.124.64:36270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hartflicker.com"] [uri "/.env.save"] [unique_id "apzW5ZCZV9YBHfLsvv7OCQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-06 02:31:22
(2 hours ago)
104.196.124.64 - - [06/Sep/2026:04:31:22 +0200] "GET /backup.tgz HTTP/1.1" 404 4618 "-" "Mozilla/5.0 ...
show more
104.196.124.64 - - [06/Sep/2026:04:31:22 +0200] "GET /backup.tgz HTTP/1.1" 404 4618 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" 104.196.124.64 - - [06/Sep/2026:04:31:22 +0200] "GET /.aider.conf.yml HTTP/1.1" 404 4617 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" 104.196.124.64 - - [06/Sep/2026:04:31:22 +0200] "GET /backup.7z HTTP/1.1" 404 4617 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
show less
Brute-Force
🇩🇪
Hazzard
2026-09-06 02:30:59
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:30:22
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:30:14.269047 2026] [security2:error] [pid 14187:tid 14187] [client 104.196.124.64:54298] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mikedeutsch.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mikedeutsch.com"] [uri "/mysql.sql"] [unique_id "apzQNmRMLldC_CPbDinw8gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:23:53
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:45:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:45:47.665468 2026] [security2:error] [pid 30304:tid 30304] [client 104.196.124.64:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nyemdr.com"] [uri "/.env.local"] [unique_id "apzFy8Jkx0SYADbLedLC8QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-06 00:39:32
(4 hours ago)
Login credentials theft attempt
Hacking
🇩🇪
LRob
2026-09-06 00:22:36
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-09-06 00:22 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:37:34
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.124.64 (64.124.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:37:26.424449 2026] [security2:error] [pid 25968:tid 25968] [client 104.196.124.64:57046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hellosoft.magodarman.com"] [uri "/.env.save"] [unique_id "apyntj2Vymn6XyBbmIP7DwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-05 23:32:11
(5 hours ago)
Bad_requests
Bad Web Bot
🇬🇧
consul.to
2026-09-05 23:06:59
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack