🇳🇱
homeshowdomain.nl
2026-09-07 22:00:25
(3 hours ago)
Auto-ban: >3000 req/min op 2026-09-07
Web App Attack
SSH
Hacking
🇺🇸
dot.mg
2026-09-07 10:40:04
(14 hours ago)
Bad behaviour
Web Spam
🇺🇸
TPI-Abuse
2026-09-07 09:26:49
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.239.150 (150.239.112.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.239.150 (150.239.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:26:44.874247 2026] [security2:error] [pid 22513:tid 22513] [client 136.112.239.150:27360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.andrewrmarshall.com"] [uri "/@fs/app/.env"] [unique_id "ap6DVFG9QzRIHydI6mOeOgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 09:02:18
(16 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /v1/.env /.docker/.env /images../.env /img ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /v1/.env /.docker/.env /images../.env /img../.env ...
show less
Web App Attack
🇪🇸
alferez
2026-09-07 08:32:59
(16 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:23:09
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.239.150 (150.239.112.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.239.150 (150.239.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:23:02.346203 2026] [security2:error] [pid 21363:tid 21363] [client 136.112.239.150:29344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.justkoolit.com"] [uri "/@fs/../../.env"] [unique_id "ap50Zgcf_CC77GgHbI2mVQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-09-07 07:53:36
(17 hours ago)
136.112.239.150 - - [07/Sep/2026:09:53:35 +0200] "GET /@fs/etc/passwd?raw?? HTTP/2.0" 404 15875 "-" ...
show more
136.112.239.150 - - [07/Sep/2026:09:53:35 +0200] "GET /@fs/etc/passwd?raw?? HTTP/2.0" 404 15875 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
136.112.239.150 - - [07/Sep/2026:09:53:35 +0200] "GET /@fs/.env.production?raw?? HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
136.112.239.150 - - [07/Sep/2026:09:53:35 +0200] "GET /@fs/.env.development?raw?? HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Mobile/15E148 Safari/604.1; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
136.112.239.150 - - [07/Sep/2026:09:53:35 +0200] "GET /@fs/.env.local?raw?? HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:150.2) Gecko/20100101 Firefox/150.2; compatible; GrokBot/1.0; +https://x.ai/grokbot"
...
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 07:42:41
(17 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.112.239.150 (150.239.112.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:949110) triggered by 136.112.239.150 (150.239.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:42:34.313672 2026] [security2:error] [pid 703:tid 703] [client 136.112.239.150:37690] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.spmbookings.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "ap5q6npymfBrU13A0B-woQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 07:42:31
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇧🇪
cmbplf
2026-09-07 07:35:26
(17 hours ago)
771 requests with url.path *.aws/*
134 requests with url.path */auth.json
Brute-Force
Bad Web Bot
🇫🇷
masterguru
2026-09-07 07:22:07
(17 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.112.239.150 (US/United States/150 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.112.239.150 (US/United States/150.239.112.136.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇪🇸
loadsoporte
2026-09-07 07:13:26
(18 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 07:09:48
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.239.150 (150.239.112.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.239.150 (150.239.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:09:40.499833 2026] [security2:error] [pid 6564:tid 6564] [client 136.112.239.150:27860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.xtrl.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap5jNK5EcaBrOrLAo0KnBwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 06:30:03
(18 hours ago)
CrowdSec decision: crowdsecurity/http-path-traversal-probing (origin: crowdsec)
Port Scan
🇺🇸
TPI-Abuse
2026-09-07 06:17:00
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.239.150 (150.239.112.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.239.150 (150.239.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:16:53.426346 2026] [security2:error] [pid 31822:tid 31822] [client 136.112.239.150:50338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itbcanada.com"] [uri "/@fs/../.env"] [unique_id "ap5W1ernWVLpDu6vAnw3WQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack