πΊπΈ
TPI-Abuse
2026-08-29 09:28:40
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:28:34.062341 2026] [security2:error] [pid 2015:tid 2015] [client 104.199.243.99:58664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cromaki.com"] [uri "/@fs/.env"] [unique_id "apKmQo5TPq1ToGGDMtAevAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 08:56:01
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:55:56.994754 2026] [security2:error] [pid 18514:tid 18514] [client 104.199.243.99:56984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pkmachine.com"] [uri "/@fs/.env.local"] [unique_id "apKenAw2FbvAK_FQQnOk2AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Aetherweb Ark
2026-08-29 08:43:43
(56 minutes ago)
(mod_security) mod_security (id:949110) triggered by 104.199.243.99 (TW/Taiwan/99.243.199.104.bc.goo ...
show more
(mod_security) mod_security (id:949110) triggered by 104.199.243.99 (TW/Taiwan/99.243.199.104.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 08:30:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:30:37.954593 2026] [security2:error] [pid 31680:tid 31680] [client 104.199.243.99:33750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jspd.com"] [uri "/@fs/.env.local"] [unique_id "apKYrTYDb0FRVOuS1AUCCQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-08-29 07:36:55
(2 hours ago)
Aggressive web search of vulnerable pages: /assets../.env /img../.env /src/.env /app/.env /uploads.. ...
show more
Aggressive web search of vulnerable pages: /assets../.env /img../.env /src/.env /app/.env /uploads../.env ...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 07:36:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:36:12.020462 2026] [security2:error] [pid 13207:tid 13207] [client 104.199.243.99:41666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nassariys.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apKL7PBSWJTBmsIuUu8e-gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 07:35:40
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 06:55:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:54:56.171929 2026] [security2:error] [pid 26065:tid 26065] [client 104.199.243.99:49652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "resume.martinka.org"] [uri "/@fs/src/.env"] [unique_id "apKCQN_Eo1E5qcPZpIauAAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 06:49:20
(2 hours ago)
Aggressive web scan
Web App Attack
π«π·
largo-it.net
2026-08-29 06:33:53
(3 hours ago)
[29/Aug/2026:08:33:52.319] HTTP 404 - GET /@fs/root/.aws/credentials.bak?raw??
[29/Aug/2026:08:33:53 ...
show more
[29/Aug/2026:08:33:52.319] HTTP 404 - GET /@fs/root/.aws/credentials.bak?raw??
[29/Aug/2026:08:33:53.021] HTTP 404 - GET /.env?raw??
[29/Aug/2026:08:33:53.033] HTTP 404 - GET /.env?raw??
[29/Aug/2026:08:33:53.014] HTTP 404 - GET /@fs/etc/passwd?raw??
[29/Aug/2026:08:33:53.020] HTTP 404 - GET /@fs/home/node/.aws/config?raw??
[29/Aug/2026:08:33:53.021] HTTP 404 - GET /@fs/.env.staging?raw??
[29/Aug/2026:08:33:53.022] HTTP 404 - GET /@fs/.env.development?raw??
[29/Aug/2026:08:33:53.027] HTTP 404 - GET /@fs/app/.aws/credentials?raw??
show less
Hacking
Bad Web Bot
Web App Attack
ππΊ
miszterx.hu
2026-08-29 06:06:41
(3 hours ago)
XORP (haproxy): 47x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 47x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 05:47:01
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.243.99 (99.243.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:46:55.349050 2026] [security2:error] [pid 8256:tid 8256] [client 104.199.243.99:60760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.onlinepetcaresuperstore.banis-associates.com"] [uri "/@fs/.env"] [unique_id "apJyT4srHN5mnf1zJs-kcwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
gadix
2026-08-29 05:29:18
(4 hours ago)
[29/Aug/2026:07:29:17.722146 +0200] apJuJ97z4ql3U73Vf52omgAAAAY 104.199.243.99 58502 127.0.0.1 7081
...
show more
[29/Aug/2026:07:29:17.722146 +0200] apJuJ97z4ql3U73Vf52omgAAAAY 104.199.243.99 58502 127.0.0.1 7081
[29/Aug/2026:07:29:17.837732 +0200] apJuJ-Tq2n5ZLRYHMzwuyQAAAFI 104.199.243.99 58572 127.0.0.1 7081
[29/Aug/2026:07:29:17.933327 +0200] apJuJ97z4ql3U73Vf52onwAAABU 104.199.243.99 58596 127.0.0.1 7081
...
show less
Web App Attack
π³π±
Site.eu
2026-08-29 05:17:52
(4 hours ago)
Excessive multi-domain requests
Brute-Force
π³πΏ
Antinson
2026-08-29 05:02:35
(4 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot