🇺🇸
TPI-Abuse
2026-09-06 15:14:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:14:37.108377 2026] [security2:error] [pid 11671:tid 11671] [client 104.199.229.55:58644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hppagewideprinting.com"] [uri "/img../.env"] [unique_id "ap2DXRt_8y9AFnSNEPjZEwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jormaster3k
2026-09-06 14:59:14
(2 hours ago)
Attack against Apache (too many 404s)
Web App Attack
🇷🇴
clauss
2026-09-06 14:51:45
(2 hours ago)
104.199.229.55 - - [06/Sep/2026:17:51:44 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ...
show more
104.199.229.55 - - [06/Sep/2026:17:51:44 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
104.199.229.55 - - [06/Sep/2026:17:51:44 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 404 11799 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:40:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:40:49.377720 2026] [security2:error] [pid 324:tid 324] [client 104.199.229.55:57538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dpcreamery.com"] [uri "/api/fs/read"] [unique_id "ap17cdFBu5MtLFe11rqnQQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:48:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:48:31.094604 2026] [security2:error] [pid 8870:tid 8870] [client 104.199.229.55:37892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emeraldhighlands.org"] [uri "/%2e%2e/.env"] [unique_id "ap1vL63Z2gCYzozukFBx1QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:27:22
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:27:17.769678 2026] [security2:error] [pid 29735:tid 29735] [client 104.199.229.55:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.infinitewashing.com"] [uri "/@fs/src/.env"] [unique_id "ap1qNR_sa1S-G0ChHP0bQwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:50:09
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:50:04.320577 2026] [security2:error] [pid 4724:tid 4724] [client 104.199.229.55:57192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ladymfashion.com"] [uri "/api/fs/read"] [unique_id "ap1hfIxct-Cc9SZo3CbUOwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 12:36:12
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:23:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:23:00.068306 2026] [security2:error] [pid 13370:tid 13370] [client 104.199.229.55:51704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hillerhome.com"] [uri "/@fs/app/.env"] [unique_id "ap1bJGgCayamhKX6JQFV4AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-06 11:38:48
(5 hours ago)
AutoBlock: 📡 Port Scan (Non Decay-Based)
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 10:06:06
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:06:01.523085 2026] [security2:error] [pid 5460:tid 5460] [client 104.199.229.55:34218] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jessie-wu.com|F|2"] [data ".jessie-wu.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jessie-wu.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jessie-wu.com"] [unique_id "ap07Cctkposy5y5BAxYn6QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:49:37
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:49:33.566658 2026] [security2:error] [pid 4914:tid 5034] [client 104.199.229.55:51136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.geekshop.com"] [uri "/uploads../.env"] [unique_id "ap03LXoLCFt1T2LTQBHyTgAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:15:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.229.55 (55.229.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:15:52.376433 2026] [security2:error] [pid 686696:tid 686702] [client 104.199.229.55:56182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dubarch.com"] [uri "/.env.js"] [unique_id "ap0vSFSgEw3EPmiJ5KhR0gAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 09:06:37
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-06 08:56:44
(8 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /static//home/user/.env /static//.env /med ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /static//home/user/.env /static//.env /media../.env /files../.env ...
show less
Web App Attack