🇩🇪
raph
2026-09-06 00:27:26
(7 minutes ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-06 00:08:23
(26 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 104.196.137.182 (US/United States/182.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.196.137.182 (US/United States/182.137.196.104.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 00:04:41
(30 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:04:33.500899 2026] [security2:error] [pid 8641:tid 8641] [client 104.196.137.182:40976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "juliansongs.com"] [uri "/.env.example"] [unique_id "apyuETbuS3BJHbSY6Nx-iAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:30:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:30:22.339821 2026] [security2:error] [pid 1502:tid 1502] [client 104.196.137.182:45964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.register-yacht-belgium.com"] [uri "/wp-config.php.swp"] [unique_id "apymDizvfge9yxE2R2EhrQAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 23:06:55
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:57:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:56:56.783114 2026] [security2:error] [pid 27800:tid 27800] [client 104.196.137.182:37990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jenniferpittman.com"] [uri "/.env.example"] [unique_id "apyeOLQCNcSH3bMJfOz89QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 22:56:38
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:31:16
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:31:12.573987 2026] [security2:error] [pid 15094:tid 15094] [client 104.196.137.182:34676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "torresyrellenos.com"] [uri "/wp-config.php~"] [unique_id "apyYMCIWec6R-OAHQrdEvQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:11:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.137.182 (182.137.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:10:55.362033 2026] [security2:error] [pid 31153:tid 31153] [client 104.196.137.182:38478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.eaglesnestfuelfarm.com"] [uri "/.env.old"] [unique_id "apyTbxKyLW6GKMoLPkYunwAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 22:05:19
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-05 22:02:54
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
LRob
2026-09-05 21:25:14
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-09-05 21:25 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-05 21:04:15
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-05 20:40:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-05 07:40:08
(16 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection