๐ซ๐ท
masterguru
2026-08-28 09:17:01
(4 minutes ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-193)
show less
Bad Web Bot
๐บ๐ธ
snappic
2026-08-28 09:11:34
(9 minutes ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (Windows NT 10.0; rv:127.5) Gecko/20100101 Fi ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 (Windows NT 10.0; rv:127.5) Gecko/20100101 Firefox/127.5; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-08-28 08:17:41
(1 hour ago)
(modsecurity) srv101 ModSecurity 104.196.98.4 (US/United States/4.98.196.104.bc.googleusercontent.co ...
show more
(modsecurity) srv101 ModSecurity 104.196.98.4 (US/United States/4.98.196.104.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-08-28 08:10:27
(1 hour ago)
Web application attack detected.
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-28 07:17:09
(2 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, path_traversal, aws_creds, source_backup, ssh_keys, ai_secrets, git_exposure, config_backup. Observed by 1 sensor(s); 499 hits.
show less
Hacking
Web App Attack
๐ฉ๐ช
Hary74656
2026-08-28 06:11:22
(3 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=5. No raw log data included.
Web App Attack
Anonymous
2026-08-28 05:58:12
(3 hours ago)
Bot / seems abusive / Apache connections: 76
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:57:54
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.98.4 (4.98.196.104.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.98.4 (4.98.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:57:45.561107 2026] [security2:error] [pid 2579:tid 2579] [client 104.196.98.4:17946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rheemhvac.savingshvac.com"] [uri "/@fs/.env"] [unique_id "apEjWbaUNyxblUMhAxHJJAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-28 05:42:34
(3 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 104.196.98.4 (US/United States/4.98.196.104.bc.googleuserconte ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 104.196.98.4 (US/United States/4.98.196.104.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.196.98.4 - - [28/Aug/2026:07:42:30 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 200 12029 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) Version/19.2 Mobile/15E148 Safari/604.1" "-" host=ticketingla.checkall.cloud
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-28 05:40:53
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.98.4 (4.98.196.104.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.98.4 (4.98.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:40:47.672654 2026] [security2:error] [pid 20520:tid 20520] [client 104.196.98.4:31272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mdp-interiors.com"] [uri "/@fs/.env"] [unique_id "apEfXzl08IDLUJB5sVEeJgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-28 05:27:10
(3 hours ago)
Login credentials theft attempt
Hacking
๐ฆ๐บ
AWW-Admin
2026-08-28 05:19:43
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 104.196.98.4 (US/United States/4.98.196 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.196.98.4 (US/United States/4.98.196.104.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
COMAITE
2026-08-28 05:02:32
(4 hours ago)
Common web attack from 104.196.98.4.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 04:43:19
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.98.4 (4.98.196.104.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.98.4 (4.98.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:43:12.645504 2026] [security2:error] [pid 32732:tid 32732] [client 104.196.98.4:61134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.skyfall-estate.com"] [uri "/@fs/.env"] [unique_id "apER4KFu0yb0hAiQ1C5tDAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 04:04:58
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.98.4 (4.98.196.104.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.98.4 (4.98.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:04:52.872107 2026] [security2:error] [pid 18752:tid 18752] [client 104.196.98.4:32988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.taacorp.com"] [uri "/@fs/root/.env"] [unique_id "apEI5MUIgBeDS4c0HXbIqwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack