🇧🇾
lns.bz
2026-09-06 06:23:07
(11 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:50:09
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:01.786443 2026] [security2:error] [pid 28682:tid 28682] [client 104.196.218.187:38788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.worshipconcert.com"] [uri "/.env.production"] [unique_id "apzi6avBdM1z4jp-m5upgAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:30:09
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:30:05.998101 2026] [security2:error] [pid 4336:tid 4336] [client 104.196.218.187:49288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canfieldnyc.com"] [uri "/.env.bak"] [unique_id "apzePQWmvaCjzk3NXEChwQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
ingroscart.it
2026-09-06 03:26:40
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇩🇪
Petros Stefanakis
2026-09-06 03:00:49
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 104.196.218.187 (US/United States/187.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.196.218.187 (US/United States/187.218.196.104.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:59:46
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:37.581345 2026] [security2:error] [pid 934:tid 934] [client 104.196.218.187:47270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.adirondackwaterfront.com"] [uri "/.env.old"] [unique_id "apzXGdOyvdrom1sSpJ-g9QAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-06 02:45:12
(14 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-06 02:32:35
(14 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 01:11:42
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:11:35.459382 2026] [security2:error] [pid 29582:tid 29582] [client 104.196.218.187:41184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m.97201.com"] [uri "/.env.bak"] [unique_id "apy9xyJ5mPje0NwU5eH13AAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:42:34
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:42:28.421180 2026] [security2:error] [pid 16201:tid 16201] [client 104.196.218.187:53492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "a.hvacs-aircon.com"] [uri "/wp-config.php.bak"] [unique_id "apy29IWSttXRBzOWOtNMXAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-09-06 00:10:52
(17 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:53:07
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.218.187 (187.218.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:52:58.959705 2026] [security2:error] [pid 9843:tid 9843] [client 104.196.218.187:43930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.eaglesnestfuelfarm.com"] [uri "/.env.example"] [unique_id "apyrWofYJHqdLknlfTJTEgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 23:15:33
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 22:48:56
(18 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-05 22:25:00
(19 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack