๐ฉ๐ช
FeG Deutschland
2026-09-22 16:43:12
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:24:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.209.41 (41.209.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.209.41 (41.209.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:24:48.881319 2026] [security2:error] [pid 30714:tid 30714] [client 136.107.209.41:54700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prosucomexico.com"] [uri "/.env.backup"] [unique_id "arKr0JeNIwp3FUz6a-uZeAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 15:57:05
(2 days ago)
Fail2ban Nginx log integration.
Brute-Force
SSH
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 15:30:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.209.41 (41.209.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.209.41 (41.209.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:30:53.475022 2026] [security2:error] [pid 5479:tid 5479] [client 136.107.209.41:58058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natickvillagerentals.com"] [uri "/.env"] [unique_id "arKfLV0VNyTgyeXwZIUekAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:57:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.209.41 (41.209.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.209.41 (41.209.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:57:15.604180 2026] [security2:error] [pid 17806:tid 17907] [client 136.107.209.41:58356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.theworldinstituteofslowness.com"] [uri "/.env.local"] [unique_id "arKXSxGzGO-kUtug92cTKQAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-22 14:55:12
(2 days ago)
Web App Attack
Anonymous
2026-09-22 14:55:01
(2 days ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.107.209.41 (41.209.107.136.bc.googleuser ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.107.209.41 (41.209.107.136.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.107.209.41 - - [22/Sep/2026:16:54:58 +0200] "GET /.env.old HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
136.107.209.41 - - [22/Sep/2026:16:54:58 +0200] "GET /.env.bak HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
136.107.209.41 - - [22/Sep/2026:16:54:58 +0200] "GET /.env.backup HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
show less
Port Scan
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 14:47:41
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
Aetherweb Ark
2026-09-22 14:46:14
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 136.107.209.41 (US/United States/41.209.107.136 ...
show more
(mod_security) mod_security (id:949110) triggered by 136.107.209.41 (US/United States/41.209.107.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-22 14:29:26
(2 days ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-09-22 14:06:17
(2 days ago)
[Tue Sep 22 16:06:17.043804 2026] [access_compat:error] [pid 25201:tid 25201] [client 136.107.209.41 ...
show more
[Tue Sep 22 16:06:17.043804 2026] [access_compat:error] [pid 25201:tid 25201] [client 136.107.209.41:41934] AH01797: client denied by server configuration: /var/www/html/.env.bak
[Tue Sep 22 16:06:17.044877 2026] [access_compat:error] [pid 36325:tid 36325] [client 136.107.209.41:41962] AH01797: client denied by server configuration: /var/www/html/.env.production
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 14:05:22
(2 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-22 13:38:16
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-22 13:03:51
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:28:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.209.41 (41.209.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.209.41 (41.209.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:28:19.622296 2026] [security2:error] [pid 9452:tid 9452] [client 136.107.209.41:37202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "distilledwater.net"] [uri "/.env.backup"] [unique_id "arJ0Y2QV4AL1O6kSLo4-egAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack