🇺🇸
Lee Daniel
2026-09-06 23:05:04
(1 hour ago)
104.196.29.47 - - [06/Sep/2026:19:05:03 -0400] "GET /.htpasswd HTTP/1.1" 403 6288 "https://portstcha ...
show more
104.196.29.47 - - [06/Sep/2026:19:05:03 -0400] "GET /.htpasswd HTTP/1.1" 403 6288 "https://portstcharles.com/.htpasswd" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 22:30:03
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:15:35
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.29.47 (47.29.196.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.29.47 (47.29.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:15:29.198447 2026] [security2:error] [pid 10977:tid 10977] [client 104.196.29.47:54692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rnance.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "ap3mAbmy-da7a9Wdd3IxOQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ALSCO®️
2026-09-06 22:00:23
(2 hours ago)
Report By ALSCO Security Team: Suspicious File Upload Attempt
Hacking
🇺🇸
Secure Gateway®️
2026-09-06 22:00:22
(2 hours ago)
Report By Secure Gateway Security Team: Brute Force Login Attempt
SQL Injection
Anonymous
2026-09-06 21:13:50
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇬🇧
poundawebsiteltd
2026-09-06 21:11:17
(3 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 104.196.29 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 104.196.29.47 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 104.196.29.47 (US/United States/47.29.196.104.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
🇩🇪
maxpower
2026-09-06 20:03:18
(4 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 104.196.29.47 (US/United States/47.29.196.104.bc.googleusercon ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 104.196.29.47 (US/United States/47.29.196.104.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.196.29.47 - - [06/Sep/2026:22:03:16 +0200] "GET /rclone.conf HTTP/2.0" 200 11952 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "-" host=www.post-art.eu.accademiam.com
show less
Port Scan
🇳🇱
Site.eu
2026-09-06 19:59:26
(4 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 19:25:27
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.196.29.47 (47.29.196.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 104.196.29.47 (47.29.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:25:20.738511 2026] [security2:error] [pid 16771:tid 16771] [client 104.196.29.47:48158] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wisk.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wisk.org"] [uri "/rclone.conf"] [unique_id "ap2-IJQp5CC-byfnXIyUEgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
23p02732
2026-09-06 18:25:22
(5 hours ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 18:05:10
(6 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:14:32
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.196.29.47 (47.29.196.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 104.196.29.47 (47.29.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:14:28.077736 2026] [security2:error] [pid 24681:tid 24681] [client 104.196.29.47:45018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.practicalrightsofself-defense.gemexpressions.com|F|2"] [data ".practicalrightsofself-defense.gemexpressions.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.practicalrightsofself-defense.gemexpressions.com"] [uri "/z9x8c7v6b5-debug-trigger-www.practicalrightsofself-defense.gemexpressions.com"] [unique_id "ap2RZHu10yVX6XvL-Lon3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 15:41:00
(8 hours ago)
447 requests with url.path */@fs/*
150 requests with url.path */proc/*
148 requests with url.path ...
show more
447 requests with url.path */@fs/*
150 requests with url.path */proc/*
148 requests with url.path *.oci/*
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 15:27:41
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.29.47 (47.29.196.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.29.47 (47.29.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:27:36.666919 2026] [security2:error] [pid 20056:tid 20056] [client 104.196.29.47:58316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.homehealth101.com"] [uri "/static../.env"] [unique_id "ap2GaFZn-YdSgGTL8ix6mwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack