🇫🇷
dwmp
2026-09-06 21:52:49
(3 minutes ago)
Url probing: /rclone.conf
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:36:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 146.148.18.197 (197.18.148.146.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 146.148.18.197 (197.18.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:36:51.361006 2026] [security2:error] [pid 2070:tid 2070] [client 146.148.18.197:37996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lizinkcreations.needtoorder.us"] [uri "/static//app/.env"] [unique_id "ap3O42hvvNBycK9G9RVROgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-09-06 20:02:46
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /firebase-config.json
Timestamp: 2026-09-06T18:15:36Z
Ray ID: a36f75c4fd33d87e
UA: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)
show less
Bad Web Bot
🇨🇦
polycoda
2026-09-06 19:23:13
(2 hours ago)
AutoBlock: 📡 Port Scan (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ❌ Excess ...
show more
AutoBlock: 📡 Port Scan (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:33:02
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 146.148.18.197 (197.18.148.146.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 146.148.18.197 (197.18.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:32:56.664308 2026] [security2:error] [pid 25172:tid 25172] [client 146.148.18.197:41996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lockyers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lockyers.com"] [uri "/z9x8c7v6b5-debug-trigger-lockyers.com"] [unique_id "ap2jyLVFbRfk7c61kLdRhAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Cuteminded
2026-09-06 16:56:08
(5 hours ago)
Probing for web vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:10:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.148.18.197 (197.18.148.146.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 146.148.18.197 (197.18.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:10:00.000014 2026] [security2:error] [pid 7924:tid 7924] [client 146.148.18.197:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livpure.webfrog.ws"] [uri "/api/fs/read"] [unique_id "ap10N-oxOWP7l_CeIVCHBQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:44:58
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 146.148.18.197 (197.18.148.146.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 146.148.18.197 (197.18.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:44:50.718757 2026] [security2:error] [pid 31401:tid 31401] [client 146.148.18.197:56334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bamedica.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bamedica.com"] [uri "/z9x8c7v6b5-debug-trigger-bamedica.com"] [unique_id "ap1uUpgPsuWZdOwevpDPhgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 12:41:22
(9 hours ago)
421 requests with url.path */@fs/*
157 requests with url.path *.oci/*
Brute-Force
Bad Web Bot
🇺🇸
Charlesiv
2026-09-06 12:06:33
(9 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /nginx_status
Timestamp: 2026-09-06T11:54:14Z
Ray ID: a36d47214ea79e9c
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)
show less
Bad Web Bot
🇬🇧
thetomtaylor.co.uk
2026-09-06 11:06:00
(10 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01]
Hacking
SQL Injection
Web App Attack
Anonymous
2026-09-06 10:35:52
(11 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-06 10:10:03
(11 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-06 10:08:01
(11 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice02,wa01,wa02]
Hacking
SQL Injection
Web App Attack
🇷🇴
clauss
2026-09-06 09:29:28
(12 hours ago)
146.148.18.197 - - [06/Sep/2026:12:29:26 +0300] "GET /rclone.conf HTTP/2.0" 403 129 "-" "Mozilla/5.0 ...
show more
146.148.18.197 - - [06/Sep/2026:12:29:26 +0300] "GET /rclone.conf HTTP/2.0" 403 129 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
146.148.18.197 - - [06/Sep/2026:12:29:27 +0300] "GET /config.json HTTP/2.0" 404 21350 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
...
show less
Web App Attack