π¨π
backslash
2026-09-04 00:06:01
(31 minutes ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-03 23:46:39
(50 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:46:35.739139 2026] [security2:error] [pid 1591162:tid 1591220] [client 104.199.253.148:13286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.copex-ireland.com"] [uri "/@fs/.env"] [unique_id "apoG2_xnsRWV5VEWqYP_SgAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-09-03 23:46:11
(51 minutes ago)
Aggressive web search of vulnerable pages: /uploads../.env /assets../.env /images../.env /v1/.env /b ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /assets../.env /images../.env /v1/.env /backend/.env ...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 23:08:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:08:29.122314 2026] [security2:error] [pid 11722:tid 11722] [client 104.199.253.148:12654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.zenmonkeyproject.com"] [uri "/@fs/../.env"] [unique_id "apn97T4ZkVCPls-lfouX4AAAAGA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 22:31:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:31:55.024171 2026] [security2:error] [pid 9205:tid 9205] [client 104.199.253.148:17880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kittencream.com"] [uri "/@fs/app/.env"] [unique_id "apn1W8P3Z71aXo1Q9MUTKAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 22:26:25
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-03 22:08:12
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:08:06.081660 2026] [security2:error] [pid 2984:tid 2984] [client 104.199.253.148:24036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.casagrotto.com"] [uri "/@fs/root/.env"] [unique_id "apnvxisypQN9RzBpwpqHzwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
Mario Bretscher
2026-09-03 21:04:39
(3 hours ago)
[Thu Sep 03 23:04:23.956545 2026] [php:error] [pid 35867] [client 104.199.253.148:50370] script '/va ...
show more
[Thu Sep 03 23:04:23.956545 2026] [php:error] [pid 35867] [client 104.199.253.148:50370] script '/var/www/html/wp-config.php' not found or unable to stat
[Thu Sep 03 23:04:24.552471 2026] [php:error] [pid 35865] [client 104.199.253.148:50346] script '/var/www/html/config.php' not found or unable to stat
[Thu Sep 03 23:04:37.874593 2026] [php:error] [pid 35869] [client 104.199.253.148:31384] script '/var/www/html/i.php' not found or unable to stat
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 21:01:17
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:01:13.116409 2026] [security2:error] [pid 27326:tid 27326] [client 104.199.253.148:47246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.muebleriamac.com"] [uri "/@fs/.env"] [unique_id "apngGZFr5iu7tgehMifCzwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 20:50:15
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-03 20:44:21
(3 hours ago)
Aggressive web scan
Web App Attack
π΅π±
Niko's Stuff
2026-09-03 20:22:27
(4 hours ago)
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/104.199.253. ...
show more
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/104.199.253.148
show less
Web App Attack
Hacking
π¬π§
consul.to
2026-09-03 20:16:19
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
maxxsense
2026-09-03 20:14:48
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 104.199.253.148 (TW/Taiwan/148.253.199. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 104.199.253.148 (TW/Taiwan/148.253.199.104.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-03 19:51:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.253.148 (148.253.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:51:03.247875 2026] [security2:error] [pid 18290:tid 18312] [client 104.199.253.148:45458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tiltedfish.net"] [uri "/@fs/app/.env"] [unique_id "apnPp7V6ypBF3lCdd2FhegAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack