π«π·
SpaceHost-Server
2026-09-21 22:15:59
(2 days ago)
Brute-Force
Web App Attack
πΊπΈ
EvilTurkey
2026-09-21 12:17:58
(2 days ago)
Web app attack against financial institution website.
Web App Attack
Hacking
π«π·
SpaceHost-Server
2026-09-20 22:15:26
(3 days ago)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 15:23:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.2.197 (197.2.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.2.197 (197.2.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:23:41.391694 2026] [security2:error] [pid 5616:tid 5616] [client 136.108.2.197:50886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furballproductions.org"] [uri "/apps/.env"] [unique_id "aq_6fQnynQc9XcNV-93ODQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-20 15:04:59
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
WizardsToolkit
2026-09-20 14:51:54
(3 days ago)
tried to access forbidden files; attempted to access /@fs/app/.env?raw??
Web App Attack
πΊπΈ
WellSpring
2026-09-20 14:45:58
(3 days ago)
good bot honeypot on freeproduce.org/deploy/.env β WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-20 14:45:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.2.197 (197.2.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.2.197 (197.2.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:45:24.115577 2026] [security2:error] [pid 28243:tid 28243] [client 136.108.2.197:55982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "freemanfoundationcle.org"] [uri "/server/.env"] [unique_id "aq_xhJGIKXpO4XHVhOisiwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
melroy89
2026-09-20 14:41:53
(3 days ago)
136.108.2.197 - - [20/Sep/2026:16:41:18 +0200] "GET /z9x8c7v6b5-debug-trigger-freedomnames.org HTTP ...
show more
136.108.2.197 - - [20/Sep/2026:16:41:18 +0200] "GET /z9x8c7v6b5-debug-trigger-freedomnames.org HTTP/2.0" 403 93 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "freedomnames.org" 0.000
136.108.2.197 - - [20/Sep/2026:16:41:18 +0200] "GET /wp-json HTTP/2.0" 403 93 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "freedomnames.org" 0.000
136.108.2.197 - - [20/Sep/2026:16:41:18 +0200] "POST / HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "freedomnames.org" 0.001
136.108.2.197 - - [20/Sep/2026:16:41:18 +0200] "POST /graphql HTTP/2.0" 403 64 "https://freedomnames.org" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "freedomnames.org" 0.001
136.108.2.197 - - [20/Sep/2026:16:41:18 +0200] "GET /__/firebase/init.json HTTP/2.0" 403 93 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML,
...
show less
Web App Attack
πΈπͺ
vaia.cloud
2026-09-20 14:10:01
(3 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π«π·
masterguru
2026-09-20 14:09:40
(3 days ago)
Bad bot detected via UA blacklist. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (78 ...
show more
Bad bot detected via UA blacklist. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (780210-133)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-20 13:30:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.2.197 (197.2.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.2.197 (197.2.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:30:49.308263 2026] [security2:error] [pid 5934:tid 5960] [client 136.108.2.197:43610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crowns.org"] [uri "/.git/HEAD"] [unique_id "aq_gCXdtCEIx02CpOfyM0QAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨πΏ
Countryman
2026-09-20 13:26:37
(3 days ago)
IPS detection: Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass
Hacking
π¨πΏ
Countryman
2026-09-20 13:26:37
(3 days ago)
IPS detection: Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass
Hacking
π³π±
Site.eu
2026-09-20 13:13:17
(3 days ago)
Excessive multi-domain requests
Brute-Force