๐บ๐ธ
ipblock.com
2026-10-05 02:41:00
(23 hours ago)
IPBlock protected site ID [3390-wh].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
etu brutus
2026-10-05 02:31:38
(23 hours ago)
104.199.131.190 has been banned for [WebApp Pipeline]
...
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 02:30:42
(23 hours ago)
Fail2Ban apache-noscript
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-10-05 02:21:57
(23 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:20:08
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:20:02.653553 2026] [security2:error] [pid 6047:tid 6047] [client 104.199.131.190:36774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||specialtycomputer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "specialtycomputer.com"] [uri "/z9x8c7v6b5-debug-trigger-specialtycomputer.com"] [unique_id "asMJUpsUk0GTMa0PrIrvugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-05 02:02:47
(23 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 01:23:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 21:23:01.555267 2026] [security2:error] [pid 16665:tid 16665] [client 104.199.131.190:33348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||spacebooger.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "spacebooger.com"] [uri "/z9x8c7v6b5-debug-trigger-spacebooger.com"] [unique_id "asL79f8rfb4YlWYtF8h5NAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 01:19:55
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 00:56:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 20:56:04.419480 2026] [security2:error] [pid 14932:tid 14932] [client 104.199.131.190:44950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||southshorestreetrods.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "southshorestreetrods.com"] [uri "/z9x8c7v6b5-debug-trigger-southshorestreetrods.com"] [unique_id "asL1pKMI1y8OSdev_UT4qAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 00:38:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 20:38:18.652729 2026] [security2:error] [pid 13593:tid 13593] [client 104.199.131.190:54828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||southernislands.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "southernislands.com"] [uri "/z9x8c7v6b5-debug-trigger-southernislands.com"] [unique_id "asLxesK2gRfxvVg7iB_F8gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 00:31:27
(1 day ago)
104.199.131.190 - - [04/Oct/2026:19:31:26 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
104.199.131.190 - - [04/Oct/2026:19:31:26 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 104.199.131.190
104.199.131.190 - - [04/Oct/2026:19:31:26 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 104.199.131.190
104.199.131.190 - - [04/Oct/2026:19:31:26 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 104.199.131.190
104.199.131.190 - - [04/Oct/2026:19:31:26 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 104.199.131.190
104.199.131.190 - - [04/Oct/2026:19:31:26 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 104.199.131.190
104.199.131.190 - - [04/Oct/2026:19:31:26 -0500] "GET /.env.production?raw HTTP/
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 00:15:21
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 20:15:14.207431 2026] [security2:error] [pid 8107:tid 8107] [client 104.199.131.190:36086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sophcomp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sophcomp.com"] [uri "/z9x8c7v6b5-debug-trigger-sophcomp.com"] [unique_id "asLsEk44Xkc3X2MiPr88dAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-04 23:56:04
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 23:47:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.131.190 (190.131.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:47:45.580823 2026] [security2:error] [pid 17551:tid 17581] [client 104.199.131.190:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "asLloW-0uWHGT06zKDK84gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-04 23:39:35
(1 day ago)
100 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot