🇳🇱
homeshowdomain.nl
2026-09-02 21:59:53
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
🇳🇱
homeshowdomain.nl
2026-09-01 22:01:02
(3 days ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
🇧🇾
lns.bz
2026-09-01 04:45:52
(4 days ago)
.env scanning [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 04:24:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:24:47.300338 2026] [security2:error] [pid 1692:tid 1692] [client 136.108.33.250:57704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boat-registration-greece.com"] [uri "/.env"] [unique_id "apZTj-Q3SuRpNVypvb0lvQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-01 04:24:47
(4 days ago)
Multiple WAF Violations
Web App Attack
🇫🇷
dynamix
2026-09-01 04:10:13
(4 days ago)
Multiple WAF Violations
Web App Attack
🇳🇴
jad-abuse
2026-09-01 03:08:04
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ignition_ ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ignition_debug, scanner_ua, env_probe, source_backup, actuator, config_backup. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 03:04:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:04:19.359478 2026] [security2:error] [pid 17997:tid 17997] [client 136.108.33.250:50214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beeswaxnews.halotoys.com"] [uri "/.env.backup"] [unique_id "apZAs_gdCfs10IKXI95vWAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 02:36:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:36:09.087358 2026] [security2:error] [pid 21694:tid 21694] [client 136.108.33.250:37628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.berkelmiami.com"] [uri "/wp-config.php.swp"] [unique_id "apY6GTfE_9Y4-hM1WCuotwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-01 01:05:37
(4 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 00:17:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:17:25.080690 2026] [security2:error] [pid 16945:tid 16945] [client 136.108.33.250:47514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pdc14.com"] [uri "/wp-config.php.bak"] [unique_id "apYZlSR4kgBifi-7aFJL3AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 23:35:15
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:35:10.498344 2026] [security2:error] [pid 23394:tid 23394] [client 136.108.33.250:53768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cgiaquaticcare.com"] [uri "/.env.example"] [unique_id "apYPrlHXFw5OGNrFAEbP6gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 22:33:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:33:00.152345 2026] [security2:error] [pid 21499:tid 21499] [client 136.108.33.250:39232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barecreationsaz.abilityengraving.com"] [uri "/.env.backup"] [unique_id "apYBHA4A0h7bF_WscT1qOQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 22:10:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.33.250 (250.33.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:10:51.135566 2026] [security2:error] [pid 17968:tid 17968] [client 136.108.33.250:38540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atomicmc.com"] [uri "/.env.save"] [unique_id "apX7695WBUUE0uaS2GXj2AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 22:05:01
(4 days ago)
suspicious request in access.log
Web App Attack