🇬🇧
thetomtaylor.co.uk
2026-09-07 11:06:00
(7 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01]
Hacking
SQL Injection
Web App Attack
🇺🇸
mnsf
2026-09-07 11:05:16
(7 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:36:23
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.44.104 (104.44.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.44.104 (104.44.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:36:19.910178 2026] [security2:error] [pid 22337:tid 22337] [client 136.112.44.104:3364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ocmtx.org"] [uri "/@fs/.env.local"] [unique_id "ap6ToyWR1-bzR2C0mSzT3wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-07 10:08:00
(8 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice02,wa01,wa02]
Hacking
SQL Injection
Web App Attack
🇫🇷
Octopuce
2026-09-07 10:01:16
(9 hours ago)
Aggressive web search of vulnerable pages: /.env.local /.env /v1/.env /.docker/.env /uploads../.env ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /v1/.env /.docker/.env /uploads../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:56:36
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.44.104 (104.44.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.44.104 (104.44.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:56:28.643307 2026] [security2:error] [pid 19714:tid 19794] [client 136.112.44.104:22424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.atechtransmission.ceol.us"] [uri "/@fs/../.env"] [unique_id "ap58PImzlBSkoifuMS83DgAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
tentwentyfour
2026-09-07 07:24:17
(11 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:57:07
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.112.44.104 (104.44.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 136.112.44.104 (104.44.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:56:59.891877 2026] [security2:error] [pid 2603:tid 2603] [client 136.112.44.104:34662] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.donate.freedrm.org"] [uri "/@fs/app/.env"] [unique_id "ap5gO_Nf7PIxRxizln2AvgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 06:42:39
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 06:29:00
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.44.104 (104.44.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.44.104 (104.44.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:28:53.577009 2026] [security2:error] [pid 30895:tid 30895] [client 136.112.44.104:53954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rsrtelecom.net"] [uri "/@fs/src/.env"] [unique_id "ap5ZpRYdfFsbHT4hRqAutQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-07 06:10:12
(12 hours ago)
Web App Attack
Anonymous
2026-09-07 06:09:51
(12 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-07 06:08:28
(12 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/root/.env (+11 more) | 2026-09-07 06:08 UTC
show less
Hacking
Web App Attack
🇩🇪
Hazzard
2026-09-07 06:06:23
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇧🇪
cmbplf
2026-09-07 05:39:39
(13 hours ago)
463 requests with url.path *.azure/*
133 requests with url.path */auth.json
Brute-Force
Bad Web Bot