Anonymous
2026-10-05 18:19:21
(11 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 17:09:57
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 13:09:51.095220 2026] [security2:error] [pid 31647:tid 31647] [client 104.196.231.14:49660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rentaroller.com.au"] [uri "/static../.env"] [unique_id "asPZ3-N4cvz5lF6HsR_FtgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 15:09:27
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 11:09:23.446354 2026] [security2:error] [pid 29684:tid 29684] [client 104.196.231.14:52964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ashtangayogamelbourne.com.au"] [uri "/.htpasswd"] [unique_id "asO9ox1Rhh90OjHoxBsWrgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
snappic
2026-10-05 10:47:24
(18 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)]
Bad Web Bot
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-05 10:34:39
(18 hours ago)
05/Oct/2026:10:34:38 +0000;104.196.231.14;"/dist/manifest.json"
05/Oct/2026:10:34:38 +0000;104.196.2 ...
show more
05/Oct/2026:10:34:38 +0000;104.196.231.14;"/dist/manifest.json"
05/Oct/2026:10:34:38 +0000;104.196.231.14;"/.vite/manifest.json"
05/Oct/2026:10:34:38 +0000;104.196.231.14;"/dist/.vite/manifest.json"
05/Oct/2026:10:34:38 +0000;104.196.231.14;"/z9x8c7v6b5-debug-trigger-app.bluegingerphotography.com.au"
05/Oct/2026:10:34:38 +0000;104.196.231.14;"/cu5q6n9xi7m502ksmmu7"
05/Oct/2026:10:34:38 +0000;104.196.231.14;"/lib/terminal-xhr.php"
05/Oct/2026:10:34:38 +0000;104.196.231.14;"/js/-CDYRsAXo.js"
...
show less
Web Spam
Brute-Force
Web App Attack
๐ฆ๐บ
FireGuard Server
2026-10-05 07:50:12
(21 hours ago)
Blocked by os-abuseipdb; 4 hits, proto=tcp, ports=80
Port Scan
Hacking
Anonymous
2026-10-05 07:30:03
(21 hours ago)
Automated report (2026-10-05T15:30:03+08:00). Scraper detected. AI scanner notorious for flooding an ...
show more
Automated report (2026-10-05T15:30:03+08:00). Scraper detected. AI scanner notorious for flooding and DDoS attacks detected.
show less
Bad Web Bot
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 07:27:05
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:26:58.348134 2026] [security2:error] [pid 29332:tid 29332] [client 104.196.231.14:38478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whipchecks.com.au"] [uri "/.htpasswd"] [unique_id "asNRQg-WA-_brCVIvbu1_QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Bay13
2026-10-05 07:13:07
(22 hours ago)
CrowdSec:custom/http-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:01:09
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:01:04.843437 2026] [security2:error] [pid 1234:tid 1234] [client 104.196.231.14:34318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rohanbyles.com.au"] [uri "/.htpasswd"] [unique_id "asM9IOXavllyjhk6DOXVqQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-10-05 03:19:32
(1 day ago)
Excessive HTTP request rate
Web App Attack
๐ฆ๐บ
ghel
2026-10-05 00:43:38
(1 day ago)
104.196.231.14 - - [05/Oct/2026:08:43:35 +0800] "GET /vjmt6arxjjib5fz2joci HTTP/1.1" 404 127475 "-" ...
show more
104.196.231.14 - - [05/Oct/2026:08:43:35 +0800] "GET /vjmt6arxjjib5fz2joci HTTP/1.1" 404 127475 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
104.196.231.14 - - [05/Oct/2026:08:43:35 +0800] "GET /uzey9ox2rqjledhym39p HTTP/1.1" 404 91239 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
104.196.231.14 - - [05/Oct/2026:08:43:35 +0800] "POST /lib/terminal-xhr.php HTTP/1.1" 404 131395 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
104.196.231.14 - - [05/Oct/2026:08:43:35 +0800] "GET /static/manifest.json HTTP/1.1" 404 131418 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
104.196.231.14 - - [05/Oct/2026:08:43:35 +0800] "GET /manifest.json HTTP/1.1" 404 131418 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-05 00:29:18
(1 day ago)
[Mon Oct 05 11:29:17.775416 2026] [security2:error] [pid 49618] [client 104.196.231.14:42928] [clien ...
show more
[Mon Oct 05 11:29:17.775416 2026] [security2:error] [pid 49618] [client 104.196.231.14:42928] [client 104.196.231.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "furst.com.au"] [uri "/css../.env"] [unique_id "asLvXQeslkRiT-f08AfMuQAAABY"]
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-10-04 23:38:26
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 22:01:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.231.14 (14.231.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:01:09.975680 2026] [security2:error] [pid 8615:tid 8615] [client 104.196.231.14:59800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comsew.com.au"] [uri "/.htpasswd"] [unique_id "asLMpcGOpou2U4fC4QSmngAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack