๐ซ๐ท
SpaceHost-Server
2026-09-21 22:14:39
(7 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 06:17:14
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:17:07.212232 2026] [security2:error] [pid 658:tid 658] [client 104.199.223.151:39978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "loupgarourugs.freerein.info"] [uri "/docker/.env"] [unique_id "arDL4-Ovv6zTmvkBTfj0EwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-21 05:35:36
(1 day ago)
{"level":"info","ts":1789968929.407791,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1789968929.407791,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"104.199.223.151","remote_port":"35220","client_ip":"104.199.223.151","proto":"HTTP/2.0","method":"POST","host":"status.nikkis.info","uri":"/graphql","headers":{"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Microsoft Edge\";v=\"152\""],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Accept":["*/*"],"Priority":["u=1, i"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Mode":["cors"],"Referer":["https://status.nikkis.info"],"Content-Type":["application/json"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"],"Sec-Fetch-Site":["same-origin"],"Sec-Fetch-Dest":["empty"],"Cookie":["REDACTED"],"Accept-Language":["en-US,en;q=0.9"],"Content-Length":["86"],"Origin":["https://status.nikkis.info"]},"tls":{"resumed":false,"version":772,"cipher_sui
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-21 05:35:12
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:19:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:19:19.367072 2026] [security2:error] [pid 24323:tid 24404] [client 104.199.223.151:42700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.draas.info"] [uri "/.env.js"] [unique_id "arC-VwKC5Yw3N_6gqchhZwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-21 04:57:37
(1 day ago)
Aggressive web search of vulnerable pages: /services/.env /packages/.env /public/.env /apps/.env /ap ...
show more
Aggressive web search of vulnerable pages: /services/.env /packages/.env /public/.env /apps/.env /api/v1/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:45:40
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.199.223.151 (151.223.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.223.151 (151.223.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:45:35.768790 2026] [security2:error] [pid 14161:tid 14175] [client 104.199.223.151:56372] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.jaedanhiggins.info|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.jaedanhiggins.info"] [uri "/ssl/localhost.key"] [unique_id "arC2b7RCwF4hW-EAs-Zp1AAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-21 04:26:47
(1 day ago)
Try to access /.aws/config
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-09-21 04:13:36
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 104.199.223.151 (TW/Taiwan/151.223.199. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.199.223.151 (TW/Taiwan/151.223.199.104.bc.googleusercontent.com)
show less
SQL Injection
๐ต๐ฑ
TaKeN
2026-09-21 02:25:54
(1 day ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-09-21T04:25:54+02:00 and 2026-09-21T04:25:54+02:00. Sample requested paths: /project/.env.
show less
Web App Attack
Hacking
๐บ๐ธ
entangled_mongoose
2026-09-21 02:21:43
(1 day ago)
Probed /info.php.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:55:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:55:49.852829 2026] [security2:error] [pid 3615294:tid 3615294] [client 104.199.223.151:32914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cypraea.info"] [uri "/internal/.env"] [unique_id "arCOpWuXQY-z-SdDy73zEwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:21:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:21:32.516178 2026] [security2:error] [pid 30307:tid 30307] [client 104.199.223.151:54556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ibermar.info"] [uri "/packages/.env"] [unique_id "arCGnLKtE0WVZ0evWkvxWAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-09-21 01:11:28
(1 day ago)
Attempted access to sensitive endpoint (/.env.js) detected. Automated scan or unauthorized probing.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:33:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.223.151 (151.223.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:33:31.304650 2026] [security2:error] [pid 24598:tid 24598] [client 104.199.223.151:35428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.visionremota.info"] [uri "/.env.example"] [unique_id "arB7W2vRNtxa61HqfLGLIwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack