๐ฌ๐ง
consul.to
2026-08-26 17:16:10
(5 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐จ๐ญ
4server
2026-08-26 17:13:26
(8 minutes ago)
[WedAug2619:13:21.9037522026][security2:error][pid1237391:tid1237621][client104.197.49.166:0]ModSecu ...
show more
[WedAug2619:13:21.9037522026][security2:error][pid1237391:tid1237621][client104.197.49.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"buonviaggio.ch\"][uri\"/.git/config\"][unique_id\"ao8esSqdj2U15HiVOFCcKQAAAMs\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-26 17:07:27
(14 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-08-26 16:54:46
(26 minutes ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 15:14:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 11:14:14.964557 2026] [security2:error] [pid 28434:tid 28434] [client 104.197.49.166:24722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alanrmariotti.com"] [uri "/.git/config"] [unique_id "ao8CxkwTnKSiApqcx2XrFgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 10:27:54
(6 hours ago)
104.197.49.166 detected and blocked by apache-modsecurity after 1 try
Brute-Force
๐ฉ๐ช
BlueWire Hosting
2026-08-26 09:38:20
(7 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:33:57
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:33:52.611727 2026] [security2:error] [pid 28808:tid 28808] [client 104.197.49.166:42294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cathybermanmft.com"] [uri "/.git/config"] [unique_id "ao6zAL-IKqgNrATUo41L6AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 08:57:02
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:56:55.077575 2026] [security2:error] [pid 5764:tid 5764] [client 104.197.49.166:58148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scala-global.com"] [uri "/.env"] [unique_id "ao6qVxpogRsSudKWqgzJLgAAAGE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 05:20:57
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:20:51.151146 2026] [security2:error] [pid 13194:tid 13194] [client 104.197.49.166:42710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sawmat.com"] [uri "/.env"] [unique_id "ao53s3hSTgMXf2SMNEkEFwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 04:48:37
(12 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.savouras.gr; logs=/var/log/httpd/access_log,/var/log/htt ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.savouras.gr; logs=/var/log/httpd/access_log,/var/log/httpd/domains/savouras.gr.log; samples=/.env | /.git/config | /.env.bak
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-08-26 02:26:51
(14 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-08-26 02:26 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 02:08:23
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:08:19.277801 2026] [security2:error] [pid 12043:tid 12043] [client 104.197.49.166:7746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saudigreenrecycling.com"] [uri "/.env"] [unique_id "ao5Kk7lFztYhqxef9JtlcAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 00:22:02
(16 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php-backup HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 00:18:27
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.49.166 (166.49.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:18:23.325627 2026] [security2:error] [pid 30029:tid 30029] [client 104.197.49.166:17460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sasquatchproductionsltd.com"] [uri "/.env"] [unique_id "ao4wz2oxXD2MnwNJtMUAPAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack