๐บ๐ธ
TPI-Abuse
2026-09-22 16:36:41
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:36:36.875797 2026] [security2:error] [pid 30785:tid 30785] [client 136.115.95.64:37178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blc2.co"] [uri "/wp/.env"] [unique_id "arKulP8VjSI37kDjmBw60gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 16:35:03
(32 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
Marten Mark
2026-09-22 16:26:23
(41 minutes ago)
136.115.95.64 - - [22/Sep/2026:16:26:22 +0000] "GET /__vite_rsc_findSourceMapURL?filename=file:///ro ...
show more
136.115.95.64 - - [22/Sep/2026:16:26:22 +0000] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 404 22988 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Web App Attack
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-22 16:23:21
(44 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:43:23
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 136.115.95.64 (64.95.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.115.95.64 (64.95.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:43:19.252983 2026] [security2:error] [pid 11713:tid 11713] [client 136.115.95.64:44786] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||epetsure.co|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "epetsure.co"] [uri "/rclone.conf"] [unique_id "arKiF_BMiLOleHU27eJEVwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:23:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:23:40.123501 2026] [security2:error] [pid 4464:tid 4464] [client 136.115.95.64:44914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalhotels.com.co"] [uri "/@fs/src/.env"] [unique_id "arKdfEpDULvZt-pUX7ezcwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
WebNiraj
2026-09-22 15:14:21
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 136.115.95.64 (US/United States/64.95.115.136.b ...
show more
(mod_security) mod_security (id:949110) triggered by 136.115.95.64 (US/United States/64.95.115.136.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 15:00:54
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:00:46.422814 2026] [security2:error] [pid 19899:tid 19899] [client 136.115.95.64:58228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integratic.com.co"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "arKYHu1Nq6GIXfPP22nKtQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 12:02:57
(5 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 10:04:11
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:04:07.973277 2026] [security2:error] [pid 32450:tid 32450] [client 136.115.95.64:43724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sguard.co"] [uri "/packages/.env"] [unique_id "arJSl7sUkf01MjQXnebAmQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-09-22 09:25:25
(7 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 09:06:48
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.115.95.64 (64.95.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.115.95.64 (64.95.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:06:42.993531 2026] [security2:error] [pid 17366:tid 17366] [client 136.115.95.64:43792] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swinjury.co|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swinjury.co"] [uri "/privatekey.key"] [unique_id "arJFIigKIYylfd4HubjMtwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 06:53:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.95.64 (64.95.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 02:52:52.886583 2026] [security2:error] [pid 4071:tid 4071] [client 136.115.95.64:45248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waleed.co"] [uri "/docker/.env"] [unique_id "arIlxJPLZOpn_Y4gKVbxpAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack