🇳🇱
homeshowdomain.nl
2026-09-07 21:59:44
(15 hours ago)
Auto-ban: >3000 req/min op 2026-09-07
Web App Attack
SSH
Hacking
🇳🇱
BlueWire Hosting
2026-09-07 10:11:43
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:35:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:35:01.261815 2026] [security2:error] [pid 440:tid 440] [client 136.112.61.106:29208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cityslickerstomp.info"] [uri "/@fs/../../.env"] [unique_id "ap6FRZAwpF37R62BDRfWngAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Jimbo67
2026-09-07 09:21:48
(1 day ago)
Cloudflare WAF: 50 hits in 30s | action=block | abuse=suspicious_probe | categories=19,21 | rule_id= ...
show more
Cloudflare WAF: 50 hits in 30s | action=block | abuse=suspicious_probe | categories=19,21 | rule_id=3329c9d804134f3e89780d69bfd872dc | URIs=/.docker/.env,/.env.backup,/@fs/..%252f..%252f..%252f..%252f..%252froot/.env??raw??,/@fs/../.env??raw??,/@fs/.env.development??raw?? | confidence=0.85
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:15:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:15:39.168156 2026] [security2:error] [pid 25134:tid 25134] [client 136.112.61.106:51322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centuryabsinthe.com"] [uri "/@fs/.env"] [unique_id "ap6Au9SwnayfQ0kSi9maxwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
palzer.IT
2026-09-07 08:56:27
(1 day ago)
Fail2ban automatic report for plesk-apache-badbot: 136.112.61.106 - - [07/Sep/2026:10:56:11 +0200] G ...
show more
Fail2ban automatic report for plesk-apache-badbot: 136.112.61.106 - - [07/Sep/2026:10:56:11 +0200] GET /@fs/root/rootkey.csv?raw?? [DOMAIN_REMOVED] 404 56572 [DOMAIN_REMOVED] Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +[DOMAIN_REMOVED]
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 08:30:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:30:51.087670 2026] [security2:error] [pid 28003:tid 28003] [client 136.112.61.106:57616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.grmvrr.com"] [uri "/@fs/../../.env"] [unique_id "ap52OxxPKAvtjjATbVEd-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:15:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:15:08.558880 2026] [security2:error] [pid 10276:tid 10276] [client 136.112.61.106:5982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.austinbiblestudents.org"] [uri "/@fs/app/.env"] [unique_id "ap5kfNI111lnukyVn33OPAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
SaltySoftworks
2026-09-07 07:09:32
(1 day ago)
Page: /@fs/root/rootkey.csv?raw??
Brute-Force
Web App Attack
Anonymous
2026-09-07 06:19:31
(1 day ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:06:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:05:58.866709 2026] [security2:error] [pid 8016:tid 8016] [client 136.112.61.106:37136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sneedvillefarmersmarket.com"] [uri "/@fs/.env.production"] [unique_id "ap5URuxjJbgu6n9GFUQZXgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 05:37:34
(1 day ago)
3.401 requests with url.path */@fs/*
555 requests with url.path *.azure/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 05:36:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.61.106 (106.61.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:36:43.326083 2026] [security2:error] [pid 27934:tid 27952] [client 136.112.61.106:21386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.boracayboats.com"] [uri "/@fs/.env.development"] [unique_id "ap5Na_ycdDboxcW1_5WmbQAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 05:26:03
(1 day ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
🇺🇸
NXTwoThou
2026-09-07 05:25:33
(1 day ago)
/@fs/../../.env%3Fraw%3F%3F
Web App Attack