🇺🇸
TPI-Abuse
2026-08-20 11:20:35
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 104.196.13.77 (77.13.196.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 104.196.13.77 (77.13.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 07:20:27.733457 2026] [security2:error] [pid 8648:tid 8648] [client 104.196.13.77:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cloudex.click|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cloudex.click"] [uri "/rclone.conf"] [unique_id "aobi-4iy8G_mZ0akqA2DbwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-08-20 10:12:37
(1 week ago)
Multiple WAF Violations
Web App Attack
🇪🇸
IT Infraestructura
2026-08-20 09:48:00
(1 week ago)
Illegal Resource Access Request blocked to URLs: /.git/config(GET) /.git/HEAD(GET) /.env.bak(G ...
show more
Illegal Resource Access Request blocked to URLs: /.git/config(GET) /.git/HEAD(GET) /.env.bak(GET)
show less
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-08-20 09:08:05
(1 week ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-20 07:19:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.196.13.77 (77.13.196.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.13.77 (77.13.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 03:19:25.579731 2026] [security2:error] [pid 28031:tid 28031] [client 104.196.13.77:46366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jbaydeliveries.com"] [uri "/.env.php.bak"] [unique_id "aoaqfXmHEKF-3TqbKHDUOwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-08-20 06:45:04
(1 week ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 06:30:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.196.13.77 (77.13.196.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.13.77 (77.13.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 02:30:13.733040 2026] [security2:error] [pid 28608:tid 28608] [client 104.196.13.77:44608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oposicionesyconcursos.es"] [uri "/.git/HEAD"] [unique_id "aoae9eJiHfF3hSE8r8yiEQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-08-20 05:56:15
(1 week ago)
[redacted] 104.196.13.77 - - [20/Aug/2026:06:56:13 +0100] "GET /.git/HEAD HTTP/1.1" 302 1544 0/61474 ...
show more
[redacted] 104.196.13.77 - - [20/Aug/2026:06:56:13 +0100] "GET /.git/HEAD HTTP/1.1" 302 1544 0/61474 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://[redacted]/support/amazonbot)" [redacted] 104.196.13.77 - - [20/Aug/2026:06:56:14 +0100] "GET /.git/config HTTP/1.1" 302 6763 0/50327 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://[redacted]/support/amazonbot)"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 05:49:51
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 104.196.13.77 (77.13.196.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 104.196.13.77 (77.13.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 01:49:46.748222 2026] [security2:error] [pid 17405:tid 17405] [client 104.196.13.77:41732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tradersworldmarket.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tradersworldmarket.com"] [uri "/z9x8c7v6b5-debug-trigger-tradersworldmarket.com"] [unique_id "aoaVekq-v7T_VslhxQNz0gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
openstrike.co.uk
2026-08-20 05:13:58
(1 week ago)
43 attacks on password grabbing URLs, VC URLs, config grabbing URLs (type 2), PHP URLs, env grabbing ...
show more
43 attacks on password grabbing URLs, VC URLs, config grabbing URLs (type 2), PHP URLs, env grabbing URLs:
GET /.aws/credentials HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /config/storage.yml HTTP/1.1
GET /config.php.bak HTTP/1.1
GET /app/.env HTTP/1.1
show less
Hacking
Web App Attack
🇩🇪
psauxit
2026-08-20 05:12:27
(1 week ago)
Fail2Ban - NGINX heavily bad-bot, possible vulnerability scanning and excessive crawling/scraping
Bad Web Bot
Web App Attack
Hacking
Web Spam
🇸🇬
Cloudkul Cloudkul
2026-08-20 05:11:08
(1 week ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
🇩🇪
BlueWire Hosting
2026-08-20 04:40:52
(1 week ago)
Aggressive scanning resulting into 404
Bad Web Bot
Anonymous
2026-08-20 04:31:45
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇲🇽
octageeks.com
2026-08-20 04:17:07
(1 week ago)
Wordpress malicious attack:[octablocked]
Web App Attack