Anonymous
2026-09-08 05:49:32
(16 minutes ago)
Aggressive web scan
Web App Attack
🇨🇭
zynex
2026-09-08 05:22:55
(43 minutes ago)
URL Probing: /@fs/.env
Web App Attack
🇳🇱
e.fierstra
2026-09-08 05:14:36
(51 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:46:32
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.118.220.112 (112.220.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.220.112 (112.220.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:46:25.017687 2026] [security2:error] [pid 588316:tid 588349] [client 136.118.220.112:32534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.keetons.net"] [uri "/@fs/.env"] [unique_id "ap-TIbK6im_k6s5C8zFFzwAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 04:45:36
(1 hour ago)
823 requests with url.path *config.json
Brute-Force
Bad Web Bot
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-08 04:39:29
(1 hour ago)
136.118.220.112 - - [07/Sep/2026:22:39:29 -0600] "GET /.git/config HTTP/1.1" 301 775 "-" "Mozilla/5. ...
show more
136.118.220.112 - - [07/Sep/2026:22:39:29 -0600] "GET /.git/config HTTP/1.1" 301 775 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:55:12
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.220.112 (112.220.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.220.112 (112.220.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:55:08.491377 2026] [security2:error] [pid 16078:tid 16078] [client 136.118.220.112:28768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.garyoneal.com"] [uri "/@fs/../.env"] [unique_id "ap-HHKuSO1On6nK1kLfviQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:39:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.220.112 (112.220.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.220.112 (112.220.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:39:41.238294 2026] [security2:error] [pid 18383:tid 18383] [client 136.118.220.112:63698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.stansco.com"] [uri "/@fs/root/.env"] [unique_id "ap-DfUZoh1rSzihTvPqaZAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 03:34:58
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-08 03:23:24
(2 hours ago)
2026/09/08 03:23:23 [error] 199230#199230: *337141 [client 136.118.220.112] ModSecurity: Access deni ...
show more
2026/09/08 03:23:23 [error] 199230#199230: *337141 [client 136.118.220.112] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "cloner.logiciensoft.com"] [uri "/@fs/app/.env"] [unique_id "178883780375.048389"] [ref ""], client: 136.118.220.112, server: srv.ingeltechgh.com, request: "GET /@fs/app/.env?raw?? HTTP/1.1", host: "cloner.logiciensoft.com"
2026/09/08 03:23:23 [error] 199229#199229: *337142 [client 136.118.220.112] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Va
...
show less
Brute-Force
🇪🇸
librebit
2026-09-08 02:54:36
(3 hours ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 02:53:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.220.112 (112.220.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.220.112 (112.220.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:53:00.907864 2026] [security2:error] [pid 11795:tid 11795] [client 136.118.220.112:37298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mms-boss.net"] [uri "/@fs/root/.env"] [unique_id "ap94jC6WG_rVfG67j7q_3QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Safronus
2026-09-08 02:51:07
(3 hours ago)
Banned by fail2ban jail=nginx-noscript match=$f2bV_matches
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 02:45:03
(3 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-08 02:29:52
(3 hours ago)
Blocked by CSF 13 firewall - Rule: US/United States/112.220.118.136.bc.googleusercontent.com
Web App Attack