🇺🇸
TPI-Abuse
2026-09-07 20:51:02
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:50:57.396059 2026] [security2:error] [pid 6489:tid 6600] [client 136.116.51.125:65482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.handsonresearch.com"] [uri "/@fs/.env.local"] [unique_id "ap8jscR4DbkHn2ArwI7cfgAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-07 20:13:39
(3 hours ago)
[07/Sep/2026:16:13:39.191817 --0400] ap8a80tZrdAyqh9nf98HOgAAAZE 136.116.51.125 56316 205.233.18.17 ...
show more
[07/Sep/2026:16:13:39.191817 --0400] ap8a80tZrdAyqh9nf98HOgAAAZE 136.116.51.125 56316 205.233.18.17 7080
[07/Sep/2026:16:13:39.191963 --0400] ap8a8@T9dxUO9gpczHHPTgAAAEk 136.116.51.125 56320 205.233.18.17 7080
[07/Sep/2026:16:13:39.192140 --0400] ap8a80QaTnDOhyWuef7mCQAAAQY 136.116.51.125 56318 205.233.18.17 7080
[07/Sep/2026:16:13:39.192283 --0400] ap8a8@T9dxUO9gpczHHPTwAAAEc 136.116.51.125 56324 205.233.18.17 7080
[07/Sep/2026:16:13:39.254352 --0400] ap8a80tZrdAyqh9nf98HOwAAAZg 136.116.51.125 56328 205.233.18.17 7080
...
show less
Hacking
🇸🇪
vaia.cloud
2026-09-07 20:00:03
(3 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-07 19:48:47
(3 hours ago)
377 requests with url.path *.azure/*
107 requests with url.path */auth.json
Brute-Force
Bad Web Bot
🇳🇱
Savvii
2026-09-07 19:26:26
(3 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 18:44:10
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇨🇭
Mario Bretscher
2026-09-07 18:42:52
(4 hours ago)
[Mon Sep 07 20:42:37.457483 2026] [php:error] [pid 714689] [client 136.116.51.125:63828] script '/va ...
show more
[Mon Sep 07 20:42:37.457483 2026] [php:error] [pid 714689] [client 136.116.51.125:63828] script '/var/www/html/wp-config.php' not found or unable to stat
[Mon Sep 07 20:42:37.596173 2026] [php:error] [pid 714761] [client 136.116.51.125:63792] script '/var/www/html/config.php' not found or unable to stat
[Mon Sep 07 20:42:51.239568 2026] [php:error] [pid 714778] [client 136.116.51.125:19578] script '/var/www/html/i.php' not found or unable to stat
...
show less
Web App Attack
🇪🇸
pipeline.es
2026-09-07 18:33:19
(4 hours ago)
Web scanning / probing for vulnerable paths | URL: /v1/graphql | Evidence: microsites.grupoeuropa.co ...
show more
Web scanning / probing for vulnerable paths | URL: /v1/graphql | Evidence: microsites.grupoeuropa.com 136.116.51.125 - - [07/Sep/2026:20:32:33 +0200] \"GET /v1/graphql HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:32:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:32:38.060603 2026] [security2:error] [pid 8540:tid 8540] [client 136.116.51.125:33740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lancehancock.com"] [uri "/@fs/../../.env"] [unique_id "ap8DRnTm8LUY1rNOcXVndwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-07 18:25:36
(4 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:12:53
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:12:48.399195 2026] [security2:error] [pid 26323:tid 26323] [client 136.116.51.125:43824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.raysolemfund.org"] [uri "/@fs/../../.env"] [unique_id "ap7-oLWNb3tkvrxo5TMrhAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 17:32:26
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:29:07
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:29:02.001697 2026] [security2:error] [pid 861067:tid 861082] [client 136.116.51.125:36606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.barnettbusinessgroup.com"] [uri "/@fs/.env.local"] [unique_id "ap70Xvauu5gs53CK6bwK9wAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
IVski.com
2026-09-07 17:11:43
(6 hours ago)
IVski WAF | Sensitive file probe - looking for exposed .env and .git config
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 16:45:10
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.51.125 (125.51.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:45:01.909510 2026] [security2:error] [pid 9764:tid 9764] [client 136.116.51.125:22426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.yourmac.co.uk"] [uri "/@fs/../../.env"] [unique_id "ap7qDWRNrEHYEKHOZ3RBYQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack