๐ณ๐ฑ
maxxsense
2026-09-03 20:43:56
(6 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 104.196.151.185 (US/United States/185.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.196.151.185 (US/United States/185.151.196.104.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-03 20:36:29
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.196.151.185 (185.151.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.151.185 (185.151.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:36:24.052653 2026] [security2:error] [pid 7020:tid 7020] [client 104.196.151.185:19804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thetopsportsbooks.com"] [uri "/@fs/.env"] [unique_id "apnaSGoI7NdrlVrpY0qlFQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-03 20:28:01
(22 minutes ago)
2026-09-03 22:26:53 AH01071: Got error 'Primary script unknown', referer https://www.debeeldmakelaar ...
show more
2026-09-03 22:26:53 AH01071: Got error 'Primary script unknown', referer https://www.debeeldmakelaar.nl/config.php && 2026-09-03 22:26:53 AH01071: Got error 'Primary script unknown', referer https://www.debeeldmakelaar.nl/wp-config.php && 2026-09-03 22:26:38 GET /@fs/.env.local?raw?? [301] && 262 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:13:41
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.196.151.185 (185.151.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.151.185 (185.151.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:13:37.436435 2026] [security2:error] [pid 28629:tid 28629] [client 104.196.151.185:32478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "belgium-boat-registration.com"] [uri "/@fs/app/.env"] [unique_id "apnU8fElrZkvHvLr0XCr2QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 19:51:36
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.196.151.185 (185.151.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.151.185 (185.151.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:51:30.618828 2026] [security2:error] [pid 1950:tid 1950] [client 104.196.151.185:29270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.brinkworthdungeon.com"] [uri "/@fs/../../.env"] [unique_id "apnPwuFfyef6DfpzmkTcBAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-03 19:51:28
(58 minutes ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-03 19:37:57
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
consul.to
2026-09-03 19:36:36
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-03 19:33:04
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 19:31:33
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.196.151.185 (185.151.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.151.185 (185.151.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:31:25.615883 2026] [security2:error] [pid 25840:tid 25840] [client 104.196.151.185:45838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jbcllcnet.com"] [uri "/@fs/.env"] [unique_id "apnLDcldEGVdxN1mtGv8sAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-03 18:17:22
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-09-03 18:11:22
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-09-03 18:05:30
(2 hours ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-09-03 17:43:06
(3 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ฎ๐น
VHosting
2026-09-03 17:40:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack