🇸🇬
Cloudkul Cloudkul
2026-09-08 12:18:25
(22 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 05:20:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-07 21:59:04
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-07 10:39:21
(1 day ago)
Aggressive web scan
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 21:59:09
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇧🇾
lns.bz
2026-09-06 06:18:46
(3 days ago)
Too many 404 requests [BY]
Web App Attack
🇮🇳
aks4226
2026-09-06 06:14:10
(3 days ago)
Bot search, attacking common web applications.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 05:21:24
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 136.114.170.212 (212.170.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.114.170.212 (212.170.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:21:17.464728 2026] [security2:error] [pid 20654:tid 20654] [client 136.114.170.212:35330] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||towida.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "towida.org"] [uri "/backup.sql"] [unique_id "apz4TQ4GyVGDvlhW2eQerAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:54:58
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.114.170.212 (212.170.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.170.212 (212.170.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:50.675145 2026] [security2:error] [pid 23736:tid 23736] [client 136.114.170.212:33666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.blanchebb.com"] [uri "/wp-config.php.bak"] [unique_id "apzkCm5tUyHRu7bgxHU9xwAAAG8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 03:39:02
(3 days ago)
CloudLinux/Plesk alert - host=cloudlinux5 dominio=francescacarbotti.it ip=136.114.170.212 richieste= ...
show more
CloudLinux/Plesk alert - host=cloudlinux5 dominio=francescacarbotti.it ip=136.114.170.212 richieste=198 rischio=ALTO score=11 motivi=molte_richieste,diverse_uri_uniche,alcuni_404,path_sospetti,api cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot
🇬🇧
SilverZippo
2026-09-06 03:19:06
(3 days ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.114.170.212 (212.170.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.170.212 (212.170.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:47.656101 2026] [security2:error] [pid 17846:tid 17846] [client 136.114.170.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wiszen.org"] [uri "/.env.old"] [unique_id "apzWq-VzLGUeCv-AwpZ5hAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-06 02:43:08
(3 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:38:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.114.170.212 (212.170.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.170.212 (212.170.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:38:42.510119 2026] [security2:error] [pid 22723:tid 22723] [client 136.114.170.212:56096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tugofwarrior.com.teamwakimphotography.com"] [uri "/.env.bak"] [unique_id "apzSMq9woxJtSCSsq-sjMAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:33:36
(3 days ago)
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.dev | /wp-config.php ...
show more
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.dev | /wp-config.php.bak | /.env.local
show less
Hacking
Web App Attack