πΊπΈ
TPI-Abuse
2026-08-26 19:24:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:24:17.328734 2026] [security2:error] [pid 51376:tid 51380] [client 8.229.252.249:37068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wheezer.org"] [uri "/static../.env"] [unique_id "ao89Ydhqs7pLkRqv5tsxCgAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 17:28:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:28:53.357027 2026] [security2:error] [pid 10354:tid 10354] [client 8.229.252.249:6546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kameleonquilt.com"] [uri "/app/.env"] [unique_id "ao8iVVS_KMQ_-2nPsD3x_QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 16:09:29
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:09:22.754864 2026] [security2:error] [pid 26024:tid 26024] [client 8.229.252.249:34486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.otcraftworks.com"] [uri "/static../.env"] [unique_id "ao8PsiIGwoSSPjj9tpqbqwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 15:08:23
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 11:08:17.188835 2026] [security2:error] [pid 1751:tid 1751] [client 8.229.252.249:10362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weat.net"] [uri "/@fs/../.env"] [unique_id "ao8BYaAUZIZ3qTz2nsnNLQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 14:18:27
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:18:21.452238 2026] [security2:error] [pid 32072:tid 32118] [client 8.229.252.249:19844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jaedanhiggins.info"] [uri "/.env"] [unique_id "ao71rTH-mGsmjCKOCdOmVQAAAYM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
grassau.com
2026-08-26 11:17:54
(9 hours ago)
*Port Scan* detected from 8.229.252.249 (US/United States/Oregon/The Dalles/249.252.229.8.bc.googleu ...
show more
*Port Scan* detected from 8.229.252.249 (US/United States/Oregon/The Dalles/249.252.229.8.bc.googleusercontent.com).
show less
Port Scan
πΊπΈ
mnsf
2026-08-26 11:05:26
(9 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
WellSpring
2026-08-26 10:45:00
(10 hours ago)
env leak on 984.today/static../.env β WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 10:09:48
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:09:43.377718 2026] [security2:error] [pid 22372:tid 22372] [client 8.229.252.249:49658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twilighthackers.com"] [uri "/static../.env"] [unique_id "ao67ZwoWL7OGlMPZssQVyAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 09:46:19
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:46:14.373524 2026] [security2:error] [pid 8744:tid 8744] [client 8.229.252.249:51596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.duckysoup.com"] [uri "/static../.env"] [unique_id "ao615rmTLv8Mvlaq_jg9XwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 08:56:55
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.252.249 (249.252.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:56:50.166469 2026] [security2:error] [pid 14858:tid 14858] [client 8.229.252.249:29776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hendersonsign.com"] [uri "/.env.local"] [unique_id "ao6qUgJTzo2GGAuWDo4kBAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2026-08-26 08:42:05
(12 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
π©πͺ
BlueWire Hosting
2026-08-26 08:12:40
(12 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
πΊπΈ
IndigoRidge
2026-08-26 07:33:36
(13 hours ago)
8.229.252.249 - - [26/Aug/2026:03:33:35 -0400] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.0" 404 4 ...
show more
8.229.252.249 - - [26/Aug/2026:03:33:35 -0400] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.0" 404 41198 "https://keoweeliving.com/@fs/root/.aws/credentials?raw??" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
8.229.252.249 - - [26/Aug/2026:03:33:35 -0400] "GET /.aws/credentials HTTP/1.0" 404 41198 "https://keoweeliving.com/.aws/credentials" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; [email protected] "
8.229.252.249 - - [26/Aug/2026:03:33:35 -0400] "GET /.env?raw?? HTTP/1.0" 404 41198 "https://keoweeliving.com/@fs/../.env?raw??" "Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.8062.132 Mobile Safari/537.36; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Web App Attack
πΈπͺ
vaia.cloud
2026-08-26 07:20:01
(13 hours ago)
crowdsecurity/http-wordpress_wpconfig
Brute-Force
Web App Attack