๐บ๐ธ
TPI-Abuse
2026-09-22 01:07:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:07:03.169775 2026] [security2:error] [pid 7176:tid 7176] [client 104.199.2.157:52036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bioterrorismbooks.info"] [uri "/backend/.env"] [unique_id "arHUt80pt7i4riVr8qmqQQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:14:39
(8 hours ago)
Brute-Force
Web App Attack
๐ซ๐ท
Lunix
2026-09-21 21:13:00
(10 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:18:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:17:56.650502 2026] [security2:error] [pid 675949:tid 675949] [client 104.199.2.157:39900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cypraea.info"] [uri "/.env.bak"] [unique_id "arGQ9FDgVnj-m1FdzcNgywAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 20:02:10
(11 hours ago)
Portscan: TCP/8443 (4x), TCP/8080 (4x)
Port Scan
๐ณ๐ฑ
enpepet
2026-09-21 19:49:22
(11 hours ago)
GENERAL: parametres: [url:git=] UA:Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; C ...
show more
GENERAL: parametres: [url:git=] UA:Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot URL:/.git/config
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-21 19:22:27
(11 hours ago)
104.199.2.157 - - [21/Sep/2026:20:22:25 +0100] "GET /roundcube/z9x8c7v6b5-debug-trigger-webmail.beta ...
show more
104.199.2.157 - - [21/Sep/2026:20:22:25 +0100] "GET /roundcube/z9x8c7v6b5-debug-trigger-webmail.betatechnologies.info HTTP/2.0" 404 994 "https://webmail.betatechnologies.info/z9x8c7v6b5-debug-trigger-webmail.betatechnologies.info" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
show less
Bad Web Bot
๐ฉ๐ช
Nevermind
2026-09-21 19:13:57
(12 hours ago)
104.199.2.157 - - [21/Sep/2026:21:13:57 +0200] "GET /config.json HTTP/1.1" 404 5669 "-" "Mozilla/5.0 ...
show more
104.199.2.157 - - [21/Sep/2026:21:13:57 +0200] "GET /config.json HTTP/1.1" 404 5669 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
104.199.2.157 - - [21/Sep/2026:21:13:57 +0200] "GET /.aws/credentials HTTP/1.1" 404 5669 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
104.199.2.157 - - [21/Sep/2026:21:13:57 +0200] "GET /wp-json HTTP/1.1" 404 5669 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
104.199.2.157 - - [21/Sep/2026:21:13:57 +0200] "GET /.git/config HTTP/1.1" 403 5672 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:22:31
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:22:25.395227 2026] [security2:error] [pid 6974:tid 7196] [client 104.199.2.157:51608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.marinkovich.info"] [uri "/client/.env"] [unique_id "arF14cb35Z_2CrFZ6OAEDQAAAhY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Hippoline
2026-09-21 16:50:57
(14 hours ago)
[Mon Sep 21 18:50:53.353856 2026] [authz_core:error] [pid 26096] [client 104.199.2.157:52462] AH0163 ...
show more
[Mon Sep 21 18:50:53.353856 2026] [authz_core:error] [pid 26096] [client 104.199.2.157:52462] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/document.php
[Mon Sep 21 18:50:53.401941 2026] [authz_core:error] [pid 24411] [client 104.199.2.157:52444] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/index.php
[Mon Sep 21 18:50:53.411464 2026] [authz_core:error] [pid 26453] [client 104.199.2.157:52474] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/phpinfo.php
[Mon Sep 21 18:50:53.415399 2026] [authz_core:error] [pid 24411] [client 104.199.2.157:52444] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/index.php
[Mon Sep 21 18:50:53.420060 2026] [authz_core:error] [pid 24253] [client 104.199.2.157:52426] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/info.php
[Mon Sep 21 18:50:53.434093 2026] [authz_core:error] [pid 24411] [client 104
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:27:33
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:27:28.005573 2026] [security2:error] [pid 14017:tid 14017] [client 104.199.2.157:45526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.studio716.info"] [uri "/.env.old"] [unique_id "arFa8NrUUsyfD14FepTpagAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 15:29:40
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
middelkoopcc
2026-09-21 15:09:01
(16 hours ago)
2026-09-21 17:07:16 GET /@fs/.env?import&?raw?? [301] && 2026-09-21 17:07:16 GET /@fs/proc/self/cmdl ...
show more
2026-09-21 17:07:16 GET /@fs/.env?import&?raw?? [301] && 2026-09-21 17:07:16 GET /@fs/proc/self/cmdline?raw?? [301] && 2026-09-21 17:07:16 GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token?raw?? [301] && 237 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:08:49
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.2.157 (157.2.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:08:45.076665 2026] [security2:error] [pid 26582:tid 26582] [client 104.199.2.157:51196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ibermar.info"] [uri "/@fs/app/.env"] [unique_id "arFIfczqn0BHj1-T-iWHDgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 14:28:03
(16 hours ago)
Excessive multi-domain requests
Brute-Force