🇫🇷
SpaceHost-Server
2026-09-20 22:15:40
(11 hours ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 15:16:58
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:16:54.311608 2026] [security2:error] [pid 29223:tid 29223] [client 136.65.219.104:43408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "w360.mx"] [uri "/.env.bak"] [unique_id "aq_45rQ1f3uVU474CJRxjwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:55:30
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:55:26.610446 2026] [security2:error] [pid 14872:tid 14872] [client 136.65.219.104:55870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sierrablue.farm"] [uri "/backend/.env"] [unique_id "aq_z3ojrs5Js4wDYDhNvaQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:07:51
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:07:42.925222 2026] [security2:error] [pid 9023:tid 9023] [client 136.65.219.104:58424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lightningbug.farm"] [uri "/docker/.env"] [unique_id "aq_oruXDY4pQvlOSwzFv8AAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-20 14:06:02
(19 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:43:43
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:43:36.094545 2026] [security2:error] [pid 7357:tid 7357] [client 136.65.219.104:58266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imerka.com.mx"] [uri "/.env.example"] [unique_id "aq_jCK8xJVBtgLQ_yqghwAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Omar Martínez
2026-09-20 13:34:58
(19 hours ago)
[Sun Sep 20 07:34:55.075472 2026] [core:error] [pid 244382:tid 139864758904384] [remote 136.65.219.1 ...
show more
[Sun Sep 20 07:34:55.075472 2026] [core:error] [pid 244382:tid 139864758904384] [remote 136.65.219.104:40768] AH10244: invalid URI path (/%2e%2e/.env)
[Sun Sep 20 07:34:55.878697 2026] [core:error] [pid 244381:tid 139864784082496] [remote 136.65.219.104:40796] AH10244: invalid URI path (/static/../../../a/../../../../proc/self/environ)
...
show less
Phishing
Email Spam
Blog Spam
🇩🇪
macrob
2026-09-20 13:11:35
(20 hours ago)
2026/09/20 13:11:34 [error] 478231#478231: *18212802 access forbidden by rule, client: 136.65.219.10 ...
show more
2026/09/20 13:11:34 [error] 478231#478231: *18212802 access forbidden by rule, client: 136.65.219.104, server: finami.mx, request: "GET /.env.old HTTP/2.0", host: "finami.mx"
2026/09/20 13:11:34 [error] 478231#478231: *18210630 access forbidden by rule, client: 136.65.219.104, server: finami.mx, request: "GET /.env HTTP/2.0", host: "finami.mx"
2026/09/20 13:11:34 [error] 478235#478235: *18212716 access forbidden by rule, client: 136.65.219.104, server: finami.mx, request: "GET /.aws/credentials HTTP/2.0", host: "finami.mx"
...
show less
Web App Attack
🇺🇸
dtorrer
2026-09-20 13:00:44
(20 hours ago)
General vulnerability scan.
Port Scan
🇩🇪
rzk
2026-09-20 12:18:02
(21 hours ago)
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-eve ...
show more
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-event detection. ASN: GOOGLE-CLOUD-PLATFORM. Country: US. Timestamp: 2026-09-20T12:18:02+00:00.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 11:33:39
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:33:33.516109 2026] [security2:error] [pid 14894:tid 14894] [client 136.65.219.104:34300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calentadoresdemexico.com.mx"] [uri "/.git/config"] [unique_id "aq_EjYxN-OprDzu7arws3wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-20 11:15:22
(22 hours ago)
2026/09/20 11:15:20 [error] 478231#478231: *17958993 access forbidden by rule, client: 136.65.219.10 ...
show more
2026/09/20 11:15:20 [error] 478231#478231: *17958993 access forbidden by rule, client: 136.65.219.104, server: binixo.mx, request: "GET /pkg/.env HTTP/2.0", host: "binixo.mx"
2026/09/20 11:15:20 [error] 478231#478231: *17958993 access forbidden by rule, client: 136.65.219.104, server: binixo.mx, request: "GET /cmd/.env HTTP/2.0", host: "binixo.mx"
2026/09/20 11:15:20 [error] 478231#478231: *17958993 access forbidden by rule, client: 136.65.219.104, server: binixo.mx, request: "GET /.aws/credentials HTTP/2.0", host: "binixo.mx"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 10:55:23
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.219.104 (104.219.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 06:55:17.075304 2026] [security2:error] [pid 3132:tid 3132] [client 136.65.219.104:43650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlantahome.rehab"] [uri "/.env"] [unique_id "aq-7lfpho3ahu7XMg-m4MgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-20 10:40:45
(22 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-20 10:16:11
(23 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection