๐บ๐ธ
TPI-Abuse
2026-09-01 05:07:33
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:07:29.603696 2026] [security2:error] [pid 15504:tid 15504] [client 104.197.136.226:49712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.j3pr.com"] [uri "/.env.backup"] [unique_id "apZdkTiny81Kt2gi82QHtgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-01 02:49:37
(10 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 02:41:01
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:40:54.766978 2026] [security2:error] [pid 32661:tid 32661] [client 104.197.136.226:45346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.chevronparkett.com"] [uri "/.env.bak"] [unique_id "apY7Ntxi2KbTGbMw4LNUawAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 02:25:33
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 104.197.136.226 (US/United States/226.136.197.1 ...
show more
(mod_security) mod_security (id:949110) triggered by 104.197.136.226 (US/United States/226.136.197.104.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 02:05:29
(11 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-01 01:28:03
(11 hours ago)
Bot / scanning and/or hacking attempts: GET /crusader-404-probe HTTP/1.1, GET /actuator/configprops ...
show more
Bot / scanning and/or hacking attempts: GET /crusader-404-probe HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.dev HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 01:03:29
(12 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 00:56:16
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-01 00:48:09
(12 hours ago)
104.197.136.226 - - [31/Aug/2026:20:48:08 -0400] "GET /.env HTTP/1.1" 403 6278 "-" "crusader-worker/ ...
show more
104.197.136.226 - - [31/Aug/2026:20:48:08 -0400] "GET /.env HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:17:01
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:16:55.258438 2026] [security2:error] [pid 3081:tid 3081] [client 104.197.136.226:48856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.iconbizpromo.com"] [uri "/.env.example"] [unique_id "apYZd_0AiOVgm6bPasNpVgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 00:16:42
(12 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:21:50
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:21:47.074827 2026] [security2:error] [pid 9676:tid 9676] [client 104.197.136.226:35958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canaldumidi360.com"] [uri "/.env"] [unique_id "apYMi7zepoy8_lLvvtmaJwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-31 22:38:56
(14 hours ago)
cloudlinux2 fail2ban: 2026-09-01 00:33:53,629 fail2ban.actions [1605]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-01 00:33:53,629 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 34.77.85.98cloudlinux2 fail2ban: 2026-09-01 00:34:11,665 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 34.175.59.184cloudlinux2 fail2ban: 2026-09-01 00:34:17,278 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 104.197.136.226 - 2026-09-01 00:34:16cloudlinux2 fail2ban: 2026-09-01 00:34:17,309 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 104.197.136.226 - 2026-09-01 00:34:16cloudlinux2 fail2ban: 2026-09-01 00:34:17,262 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 104.197.136.226 - 2026-09-01 00:34:16cloudlinux2 fail2ban: 2026-09-01 00:34:17,294 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 104.197.136.226 - 2026-09-01 00:34:16cloudlinux2 fail2ban: 2026-09-01 00:34:16,283 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 34.141.62.124cloudlinux2 fail2ban: 2026-09-01 00:34:17,347 fail2ban.
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-31 22:20:11
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.136.226 (226.136.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:20:04.091088 2026] [security2:error] [pid 9691:tid 9691] [client 104.197.136.226:36084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.glslightingandcontrols.com"] [uri "/wp-config.php.swp"] [unique_id "apX-FGK7LIQFxqHdQlZC-QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 21:50:03
(15 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack