🇫🇷
IRISIO
2026-09-12 13:42:33
(35 minutes ago)
scans/SQL injection/spam posts : 246 queries
Web App Attack
SQL Injection
Anonymous
2026-09-12 13:35:16
(42 minutes ago)
☣️ WAF rule violation. Dangerous payload detected in the request.
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-12 12:30:15
(1 hour ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537. ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) | path: /.docker/config.json (+3 more) | 2026-09-12 12:30 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 12:16:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.146.193 (193.146.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.146.193 (193.146.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:16:33.134639 2026] [security2:error] [pid 26878:tid 26878] [client 104.198.146.193:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.click"] [uri "/backend/.env"] [unique_id "aqVCobK59H1VxQFDx4H3lwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇬
anotherwatcher
2026-09-12 11:05:13
(3 hours ago)
bad bot
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 10:58:46
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.198.146.193 (193.146.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.198.146.193 (193.146.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:58:39.433711 2026] [security2:error] [pid 30584:tid 30697] [client 104.198.146.193:54930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cityofmiddleton.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cityofmiddleton.org"] [uri "/rclone.conf"] [unique_id "aqUwXzvr4p8U1480HjSJ0gAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:39:37
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.198.146.193 (193.146.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.198.146.193 (193.146.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:39:33.247986 2026] [security2:error] [pid 5193:tid 5193] [client 104.198.146.193:49440] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||circlehealthcaregroup.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circlehealthcaregroup.com"] [uri "/rclone.conf"] [unique_id "aqUr5URfQBWmRGsFYtnGSQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 10:24:42
(3 hours ago)
[Sat Sep 12 12:24:21.570434 2026] [authz_core:error] [pid 25508:tid 25560] [client 104.198.146.193:4 ...
show more
[Sat Sep 12 12:24:21.570434 2026] [authz_core:error] [pid 25508:tid 25560] [client 104.198.146.193:46036] AH01630: client denied by server configuration: /var/www/cimt-precision/.htpasswd
[Sat Sep 12 12:24:37.496146 2026] [authz_core:error] [pid 25567:tid 25626] [client 104.198.146.193:58894] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php, referer: https://cimt-precision.de/login
[Sat Sep 12 12:24:39.606022 2026] [authz_core:error] [pid 25508:tid 25539] [client 104.198.146.193:58892] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-admin/, referer: https://cimt-precision.de/admin
[Sat Sep 12 12:24:40.929007 2026] [authz_core:error] [pid 25508:tid 25550] [client 104.198.146.193:58912] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-admin/, referer: https://cimt-precision.de/dashboard
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-12 10:19:30
(3 hours ago)
Aggressive web scan
Web App Attack
🇧🇷
Halux
2026-09-12 10:13:20
(4 hours ago)
104.198.146.193 Probing protected path or service
Web App Attack
🇫🇷
IRISIO
2026-09-12 09:43:18
(4 hours ago)
scans/SQL injection/spam posts : 120 queries
Web App Attack
SQL Injection
🇫🇷
david.houstin
2026-09-12 09:12:15
(5 hours ago)
104.198.146.193 - - [12/Sep/2026:11:12:07 +0200] "POST /api/graphql HTTP/2.0" 404 32324 "https://chi ...
show more
104.198.146.193 - - [12/Sep/2026:11:12:07 +0200] "POST /api/graphql HTTP/2.0" 404 32324 "https://chine.in" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 41506 -
104.198.146.193 - - [12/Sep/2026:11:12:09 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 404 34972 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 51178 -
104.198.146.193 - - [12/Sep/2026:11:12:09 +0200] "GET /id_rsa HTTP/2.0" 404 34418 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" 65261 -
104.198.146.193 - - [12/Sep/2026:11:12:11 +0200] "GET /..%2f.env HTTP/2.0" 404 265 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 452 -
104.198.146.193 - - [12/Sep/2026:11:12:11 +0200] "GET /..%2f..%2f.env HTTP/2.0" 404 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 572 -
104.198.
...
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 08:51:57
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.198.146.193 (193.146.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.198.146.193 (193.146.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:51:53.400633 2026] [security2:error] [pid 18766:tid 18766] [client 104.198.146.193:58368] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chickiesbeef.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chickiesbeef.com"] [uri "/rclone.conf"] [unique_id "aqUSqSdd7qaCOUfsfa4XdwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-12 08:02:15
(6 hours ago)
Web scanning / probing for vulnerable paths | URL: /.boto | Evidence: checkin.pt 104.198.146.193 - - ...
show more
Web scanning / probing for vulnerable paths | URL: /.boto | Evidence: checkin.pt 104.198.146.193 - - [12/Sep/2026:10:01:33 +0200] \"GET /.boto HTTP/2.0\" 404 20503 \"-\" \"Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
Anonymous
2026-09-12 07:58:02
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking