🇺🇸
TPI-Abuse
2026-09-06 00:40:34
(50 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:40:27.629569 2026] [security2:error] [pid 15131:tid 15131] [client 8.228.240.116:42558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hischurchatwork.iworklife.org"] [uri "/.env"] [unique_id "apy2exXHWdvPLN-5W3pA2AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-06 00:17:28
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 00:17:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:16:53.049523 2026] [security2:error] [pid 22176:tid 22195] [client 8.228.240.116:55162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anointedtour.com.havacubvision.com"] [uri "/.env.local"] [unique_id "apyw9fm8e7ZI0TuNKT11jAAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇰🇷
doll.gl
2026-09-06 00:14:05
(1 hour ago)
CrowdSec: Ip 8.228.240.116 performed 'crowdsecurity/http-sensitive-files' (5 events over 46.598072ms ...
show more
CrowdSec: Ip 8.228.240.116 performed 'crowdsecurity/http-sensitive-files' (5 events over 46.598072ms) at 2026-09-06 00:14:03.363491812 +0000 UTC (scenario: crowdsecurity/http-sensitive-files)
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:55:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:55:18.063415 2026] [security2:error] [pid 25134:tid 25134] [client 8.228.240.116:54568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.asiancommoditiescorporation.com"] [uri "/.env.prod"] [unique_id "apyr5kf53hvrVNfDpJM10gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 23:01:16
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:46:40
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:46:32.447466 2026] [security2:error] [pid 25578:tid 25578] [client 8.228.240.116:37634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "discountweddingnapkins.com"] [uri "/wp-config.php.swp"] [unique_id "apybyNnlGJbUN7Rgkm73fwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 22:24:56
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
mnsf
2026-09-05 22:05:43
(3 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:01:11
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:01:06.569418 2026] [security2:error] [pid 32685:tid 32685] [client 8.228.240.116:37508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ultratecnologia.activethinkers.net"] [uri "/.env.old"] [unique_id "apyRInNwmpJo5OdllSCgCgAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:39:41
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:39:35.454839 2026] [security2:error] [pid 26893:tid 26893] [client 8.228.240.116:51510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.instagenii.com"] [uri "/.env.example"] [unique_id "apyMF0ndpWHP7Zyw6w4iFQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:22:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.240.116 (116.240.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:22:02.651449 2026] [security2:error] [pid 23044:tid 23044] [client 8.228.240.116:53414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "volunteergems.com"] [uri "/wp-config.php~"] [unique_id "apyH-tiNFJojvU5cPfT2hgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-05 20:55:03
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-05 20:53:49
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-05 20:41:50
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 8.228.240.116 (US/United States/116.240.228.8.b ...
show more
(mod_security) mod_security (id:949110) triggered by 8.228.240.116 (US/United States/116.240.228.8.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack