🇳🇱
homeshowdomain.nl
2026-09-08 22:03:43
(4 hours ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
Anonymous
2026-09-08 13:12:11
(13 hours ago)
Bot / seems abusive / Apache connections: 29
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:09:31
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.47.81 (81.47.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.47.81 (81.47.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:09:24.141301 2026] [security2:error] [pid 5043:tid 5043] [client 136.66.47.81:10848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fatjesus.com"] [uri "/@fs/.env"] [unique_id "aqAJBCVxhBXtaCrHyC9AGwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DEV-DNS
2026-09-08 12:50:47
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-08 12:24:00
(14 hours ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:50:04
(15 hours ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
🇳🇱
e.fierstra
2026-09-08 11:36:24
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-08 11:20:00
(15 hours ago)
Automatically blocked due to distributed attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 10:18:33
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.47.81 (81.47.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.47.81 (81.47.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:18:30.507668 2026] [security2:error] [pid 2741:tid 2741] [client 136.66.47.81:54882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dev.budgetguard.com"] [uri "/@fs/../../.env"] [unique_id "ap_g9srnh9PqH93scnnH1gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 10:05:35
(16 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/../../.env (+10 more) | 2026-09-08 10:05 UTC
show less
Hacking
Web App Attack
🇫🇷
Stara
2026-09-08 10:05:16
(16 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:50:26
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.47.81 (81.47.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.47.81 (81.47.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:50:22.643516 2026] [security2:error] [pid 25950:tid 25950] [client 136.66.47.81:17500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.camouflagebikinis.com"] [uri "/@fs/src/.env"] [unique_id "ap_aXk8uw2iSY0ONvZUmxQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 09:45:22
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
NXTwoThou
2026-09-08 09:15:45
(17 hours ago)
/@fs/../../.env%3Fraw%3F%3F
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:59:52
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.47.81 (81.47.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.47.81 (81.47.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:59:48.440676 2026] [security2:error] [pid 16769:tid 16769] [client 136.66.47.81:30092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.xpd.us"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap_OhEm4-4ub3k7uB1LXzgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack