🇳🇱
homeshowdomain.nl
2026-09-08 21:59:28
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 19:33:48
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 19:32:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:32:17.916873 2026] [security2:error] [pid 5166:tid 5247] [client 104.198.86.250:61368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosendalsateri.com"] [uri "/@fs/root/.env"] [unique_id "aqBiwYwz1fJYo7FObpg9HQAAAVc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:15:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:15:20.966258 2026] [security2:error] [pid 6474:tid 6474] [client 104.198.86.250:10962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lawson-insurance.com"] [uri "/@fs/.env"] [unique_id "aqBeyD7LB9Pu93XVwFbauAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
david.houstin
2026-09-08 19:13:07
(1 day ago)
104.198.86.250 - - [08/Sep/2026:21:12:31 +0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HT ...
show more
104.198.86.250 - - [08/Sep/2026:21:12:31 +0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 404 1799 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
104.198.86.250 - - [08/Sep/2026:21:12:31 +0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw?? HTTP/1.1" 404 1799 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; LinkedInBot/1.0; +http://www.linkedin.com"
104.198.86.250 - - [08/Sep/2026:21:12:32 +0200] "GET /@fs/var/www/html/wp-config.php?raw?? HTTP/1.1" 404 5900 "https://www.chine-informations.com/@fs/var/www/html/wp-config.php?raw??" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)" 29051 -
104.198.86.250 - - [08/Sep/2026:21:13:05 +0200] "GET /firebase-config.json HTTP/1.1" 404 37561 "https://www.chine-informations.com/firebase-config.json" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)" 69120 -
104.198.86.250 - - [08/Sep/2026:21:13:05 +0200] "GET /app-config.jso
...
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-08 18:53:58
(1 day ago)
104.198.86.250 - - [08/Sep/2026:18:53:58 +0000] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 554 "-" "Mozi ...
show more
104.198.86.250 - - [08/Sep/2026:18:53:58 +0000] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 554 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.12) Gecko/20100101 Firefox/132.12; compatible; WhatsApp/10.0.2.1"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:44:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:44:04.798285 2026] [security2:error] [pid 5150:tid 5150] [client 104.198.86.250:34596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pasdesinfos.com"] [uri "/@fs/app/.env"] [unique_id "aqBXdHdslekw9LCpmPEFCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 17:50:35
(1 day ago)
104.198.86.250 - - [08/Sep/2026:19:50:34 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 117 "-" "Mozilla/ ...
show more
104.198.86.250 - - [08/Sep/2026:19:50:34 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 117 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:43:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:43:24.248472 2026] [security2:error] [pid 27411:tid 27426] [client 104.198.86.250:52950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wealthmanagementcommission.com.aafm.us"] [uri "/@fs/root/.env"] [unique_id "aqBJPFUfsoK6ew6GgXKamAAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 17:34:03
(1 day ago)
3.483 requests with url.path */@fs/*
828 requests with url.path *.aws/*
579 requests with url.pat ...
show more
3.483 requests with url.path */@fs/*
828 requests with url.path *.aws/*
579 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 17:14:20
(1 day ago)
Blocked by ModSec and CSF
Port Scan
🇳🇱
Site.eu
2026-09-08 16:45:04
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 16:39:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.86.250 (250.86.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:39:26.748934 2026] [security2:error] [pid 31751:tid 31751] [client 104.198.86.250:23548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.manoli.cl"] [uri "/@fs/src/.env"] [unique_id "aqA6PvjGYGNy2t8FQRPDqAAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
rh24
2026-09-08 16:31:49
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 104.198.86.250 (JP/J ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 104.198.86.250 (JP/Japan/250.86.198.104.bc.googleusercontent.com)
show less
Bad Web Bot
🇫🇷
Octopuce
2026-09-08 16:25:05
(1 day ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /.env /v1/.env /v2/.env /api/.env ...
Web App Attack