🇧🇬
HighWay
2026-09-20 15:17:45
(23 hours ago)
136.110.59.227 - - [20/Sep/2026:15:17:40 +0000] "GET /api/config HTTP/1.1" 404 64868 "-" "Mozilla/5. ...
show more
136.110.59.227 - - [20/Sep/2026:15:17:40 +0000] "GET /api/config HTTP/1.1" 404 64868 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
136.110.59.227 - - [20/Sep/2026:15:17:42 +0000] "GET /api/env HTTP/1.1" 404 60850 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-20 15:09:03
(23 hours ago)
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.110.59.227 - - [20/Sep/2026:17:08:58 +0200] "GET /web/.env HTTP/2.0" 404 1338 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 15:01:05
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.59.227 (227.59.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.59.227 (227.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:01:00.016925 2026] [security2:error] [pid 13751:tid 13751] [client 136.110.59.227:45984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intnlc.org"] [uri "/.env"] [unique_id "aq_1LISRQghfKl6VYnwOZwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 14:44:18
(1 day ago)
2026/09/20 14:44:16 [error] 4753#4753: *153392 [client 136.110.59.227] ModSecurity: Access denied wi ...
show more
2026/09/20 14:44:16 [error] 4753#4753: *153392 [client 136.110.59.227] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "idealcollegeonline.org"] [uri "/.aws/credentials"] [unique_id "178991545652.282339"] [ref ""], client: 136.110.59.227, server: idealcollegeonline.org, request: "GET /.aws/credentials HTTP/2.0", host: "idealcollegeonline.org"
2026/09/20 14:44:16 [error] 4753#4753: *153392 [client 136.110.59.227] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5'
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-20 14:34:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.59.227 (227.59.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.59.227 (227.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:34:48.254507 2026] [security2:error] [pid 23899:tid 23899] [client 136.110.59.227:33940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houston-church-of-god.org"] [uri "/config/.env"] [unique_id "aq_vCKl1bk35bd1C53fTpwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-20 14:27:30
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
WellSpring
2026-09-20 14:08:24
(1 day ago)
env leak on freeproduce.org/server/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:08:17
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 136.110.59.227 (227.59.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 136.110.59.227 (227.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:08:14.140686 2026] [security2:error] [pid 22558:tid 22558] [client 136.110.59.227:43748] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "freedrm.org"] [uri "/.env.backup"] [unique_id "aq_ozn7A3MVsnqgS7Gs5tAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
creechy
2026-09-20 14:00:04
(1 day ago)
136.110.59.227 - - [20/Sep/2026:06:59:57 -0700] "GET /.env.example HTTP/1.1" 404 764 "-" "Mozilla/5. ...
show more
136.110.59.227 - - [20/Sep/2026:06:59:57 -0700] "GET /.env.example HTTP/1.1" 404 764 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Hacking
Bad Web Bot
🇬🇧
Comberton
2026-09-20 13:50:45
(1 day ago)
Ban via by F2B interproj-org-access jail
Brute-Force
🇫🇷
dynamix
2026-09-20 13:46:49
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:28:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.59.227 (227.59.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.59.227 (227.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:28:27.662263 2026] [security2:error] [pid 15835:tid 15835] [client 136.110.59.227:42236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coolingsprings.org"] [uri "/.env.old"] [unique_id "aq_feysqLyso5EwGNMBDPQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:16:18
(1 day ago)
LogGuard auto-report | score=110 | flags=flood | reasons=[+35] burst_10s_hard: 135 req in 10s (thres ...
show more
LogGuard auto-report | score=110 | flags=flood | reasons=[+35] burst_10s_hard: 135 req in 10s (threshold 100); [+25] error_ratio_severe: 81% error rate in 60s (110/135); [+25] path_diversity_severe: 127 unique paths in 60s (threshold 50); [+25] probe_paths: Hit 75 known probe paths: /.aws/config, /.docker/config.json, /.env, /.env.backup, /.env.bak
show less
DDoS Attack
🇳🇱
middelkoopcc
2026-09-20 13:09:01
(1 day ago)
2026-09-20 15:07:34 AH10244: invalid URI path (/%2e%2e/.env) && 2026-09-20 15:07:36 AH10244: invalid ...
show more
2026-09-20 15:07:34 AH10244: invalid URI path (/%2e%2e/.env) && 2026-09-20 15:07:36 AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../proc/self/environ) && 2026-09-20 15:07:36 AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ) && 245 more within 20 minutes
show less
Web App Attack
Anonymous
2026-09-20 13:01:02
(1 day ago)
...
Web App Attack