๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-29 12:48:45
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-26 22:10:47
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 19:31:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 15:31:19.216294 2026] [security2:error] [pid 10371:tid 10407] [client 104.199.87.177:36754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catch-22productions.com"] [uri "/.git/config"] [unique_id "argdh590Sb-uUPOmELu5YQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 16:02:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 12:01:59.637337 2026] [security2:error] [pid 17899:tid 17899] [client 104.199.87.177:57148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.walkwithmeboston.com"] [uri "/.git/config"] [unique_id "arfsdw52JdriIeYW-QgBPAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:29:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:29:24.605004 2026] [security2:error] [pid 18169:tid 18169] [client 104.199.87.177:59432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.walkerweb.com"] [uri "/.git/config"] [unique_id "arfk1EDnjHb6SuY-u7tpGgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:10:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:10:39.717579 2026] [security2:error] [pid 18414:tid 18414] [client 104.199.87.177:49416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.waleed-alshalan.com"] [uri "/.git/config"] [unique_id "arfgb8jNx89aUapsdA10UgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 21:38:41
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 17:38:36.360656 2026] [security2:error] [pid 11738:tid 11738] [client 104.199.87.177:51382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cosmicdebris.org"] [uri "/.git/config"] [unique_id "arWYXBJwNl6Y_coEUkeqpgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 20:02:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:02:18.375689 2026] [security2:error] [pid 7316:tid 7350] [client 104.199.87.177:37208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cornell61.org"] [uri "/.git/config"] [unique_id "arWBylZEwBGzjUVxHmSklQAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:35:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:35:47.693661 2026] [security2:error] [pid 11555:tid 11555] [client 104.199.87.177:57782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.coolingsprings.org"] [uri "/.git/config"] [unique_id "arVtg594uOg6yseZMk2qFAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
snhosting
2026-09-24 14:18:35
(5 days ago)
104.199.87.177 - - [24/Sep/2026:16:18:25 +0200] "GET /.git/config HTTP/1.1" 400 158 "-" "Mozilla/5.0 ...
show more
104.199.87.177 - - [24/Sep/2026:16:18:25 +0200] "GET /.git/config HTTP/1.1" 400 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.87.177 - - [24/Sep/2026:16:18:25 +0200] "GET /.env HTTP/1.1" 400 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.87.177 - - [24/Sep/2026:16:18:25 +0200] "GET /.env.local HTTP/1.1" 400 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.87.177 - - [24/Sep/2026:16:18:25 +0200] "GET /.env.production HTTP/1.1" 400 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.199.87.177 - - [24/Sep/2026:16:18:25 +0200] "GET /.env.staging HTTP/1.1" 400 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Ge
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
Philister11
2026-09-24 02:15:11
(6 days ago)
CrowdSec: crowdsecurity/http-sensitive-files (BE/AS396982)
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 21:59:34
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
๐บ๐ธ
Mundo Bueno
2026-09-22 09:51:27
(1 week ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /.env.development [RATE LIMITED - 1800s quarantine] | Pa ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /.env.development [RATE LIMITED - 1800s quarantine] | Pays: BE | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.3
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:49:20
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.87.177 (177.87.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:49:15.498565 2026] [security2:error] [pid 12835:tid 12835] [client 104.199.87.177:36736] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/.env.bak"] [unique_id "arGmW1a4UHhu-Cek_9LrXgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 16:20:01
(1 week ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack