🇳🇱
homeshowdomain.nl
2026-09-04 22:02:18
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 14:19:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:19:35.604319 2026] [security2:error] [pid 1267:tid 1267] [client 136.110.93.98:16476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thetribehouse.com"] [uri "/@fs/.env"] [unique_id "aprTd_6-tmOSSfGoeLevmQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:35:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:34:54.630394 2026] [security2:error] [pid 16590:tid 16590] [client 136.110.93.98:42186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.goteledata.securitymontana.com"] [uri "/@fs/.env"] [unique_id "aprI_i6SYyb0GnUmbC0UmAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 12:55:06
(1 day ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:54:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:54:44.491862 2026] [security2:error] [pid 10582:tid 10582] [client 136.110.93.98:39290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wendywonjungkim.com"] [uri "/@fs/.env"] [unique_id "apq_lANwXidgjIWtx1PR1AAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 12:22:59
(1 day ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇫🇷
dwmp
2026-09-04 11:22:30
(1 day ago)
[04/Sep/2026:13:22:30.137490 +0200] apqp9gr5kRenbLmcYh6DmgAAAFg 136.110.93.98 48528 38.242.227.117 7 ...
show more
[04/Sep/2026:13:22:30.137490 +0200] apqp9gr5kRenbLmcYh6DmgAAAFg 136.110.93.98 48528 38.242.227.117 7080
[04/Sep/2026:13:22:30.137765 +0200] apqp9q6cLY9V5_KiMYg-UQAAAQc 136.110.93.98 48518 38.242.227.117 7080
[04/Sep/2026:13:22:30.139037 +0200] apqp9q6cLY9V5_KiMYg-UwAAAQA 136.110.93.98 48546 38.242.227.117 7080
...
show less
Brute-Force
SSH
🇨🇭
4server
2026-09-04 09:33:37
(1 day ago)
[FriSep0411:33:34.8177452026][security2:error][pid51663:tid51795][client136.110.93.98:0]ModSecurity: ...
show more
[FriSep0411:33:34.8177452026][security2:error][pid51663:tid51795][client136.110.93.98:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"autodiscover.mondo-it.ch\"][uri\"/@fs/root/.env\"][unique_id\"apqQbjDeWbJfAoy3qRpLNwAAANQ\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:31:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:31:10.930340 2026] [security2:error] [pid 9967:tid 9967] [client 136.110.93.98:24690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desimon.com"] [uri "/@fs/.env"] [unique_id "apqP3kbP7LSeqTqRkFxEDwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:55:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:55:27.681429 2026] [security2:error] [pid 14677:tid 14677] [client 136.110.93.98:24710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.photo-craft.org"] [uri "/@fs/root/.env"] [unique_id "app5b_WigDpZ1KYSc8cskAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:58:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:58:31.708411 2026] [security2:error] [pid 28166:tid 28166] [client 136.110.93.98:61950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.braintechsoftwaresolutions.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "appsFyyrAqXZ6c12jFkAdAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
JPPO
2026-09-04 06:55:08
(1 day ago)
370 hits : Various web attacks ...
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 06:40:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.93.98 (98.93.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:40:04.748932 2026] [security2:error] [pid 11202:tid 11202] [client 136.110.93.98:32326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cypruswatch.com"] [uri "/@fs/.env"] [unique_id "appnxLND6TgnIl-y_pZY_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 05:55:07
(1 day ago)
Portscan: TCP/8080 (2x), TCP/8443 (2x), TCP/80, TCP/443
Port Scan
🇬🇧
openstrike.co.uk
2026-09-04 05:13:40
(1 day ago)
138 attacks on password grabbing URLs, config grabbing URLs (type 2), env grabbing URLs, PHP URLs, V ...
show more
138 attacks on password grabbing URLs, config grabbing URLs (type 2), env grabbing URLs, PHP URLs, VC URLs:
GET /.aws/credentials.old HTTP/1.1
GET /config/aws.yml HTTP/1.1
GET /aws/.env.production HTTP/1.1
GET /config/aws.php HTTP/1.1
GET /.git/config HTTP/1.1
show less
Hacking
Web App Attack