🇺🇸
TPI-Abuse
2026-09-06 02:42:50
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:42:44.754967 2026] [security2:error] [pid 14158:tid 14158] [client 136.66.57.241:39726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acctusa.net"] [uri "/.env.local"] [unique_id "apzTJOEG-b2URBKfJ5kHvQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 02:09:14
(44 minutes ago)
Domain : seasonal.orchard.itrap.co.uk
Rule : env
2026-09-06 02:07:04 W3SVC291 PLESK76 217.194.212.12 ...
show more
Domain : seasonal.orchard.itrap.co.uk
Rule : env
2026-09-06 02:07:04 W3SVC291 PLESK76 217.194.212.123 GET /.env.dev - 443 - 136.66.57.241 HTTP/1.1 crusader-worker/1.0 - - seasonal.orchard.itrap.co.uk 404 0 0 7348 108 205 - -
show less
Hacking
SQL Injection
Anonymous
2026-09-06 02:06:05
(47 minutes ago)
Trying to access config files
Web App Attack
🇺🇸
mnsf
2026-09-06 02:05:31
(48 minutes ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:32:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:32:37.685135 2026] [security2:error] [pid 17439:tid 17439] [client 136.66.57.241:38044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mmmetalizing.com"] [uri "/.env"] [unique_id "apzCtU4heMDrN6Sv5q3U1AAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:49:03
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:55.922343 2026] [security2:error] [pid 20947:tid 20947] [client 136.66.57.241:38146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gizmolabs.net"] [uri "/.env.prod"] [unique_id "apy4d9rNx8M-zuUdhogC4QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-06 00:04:52
(2 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:53:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:53:14.029711 2026] [security2:error] [pid 19156:tid 19156] [client 136.66.57.241:33986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bjfrancislaw.com"] [uri "/.env.bak"] [unique_id "apyraqNFRSmfkv8nij0rvgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:56:22
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.57.241 (241.57.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:56:14.876070 2026] [security2:error] [pid 2952:tid 2961] [client 136.66.57.241:35296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bougie-bengals.com"] [uri "/.env.local"] [unique_id "apyP_qtA3Hhb7YIrmc4HQwAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 21:30:02
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇮🇹
VHosting
2026-09-05 21:10:04
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-05 21:03:17
(5 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-05 20:35:58
(6 hours ago)
Aggressive web search of vulnerable pages: /backup.tar.gz /dump.tar.gz /mysql.sql /backup.zip /backu ...
show more
Aggressive web search of vulnerable pages: /backup.tar.gz /dump.tar.gz /mysql.sql /backup.zip /backup.rar ...
show less
Web App Attack
🇺🇸
lavnet.net
2026-09-05 20:27:24
(6 hours ago)
136.66.57.241 - - [05/Sep/2026:20:27:24 +0000] "GET /database.sql HTTP/1.1" 404 4361 "-" "Mozilla/5. ...
show more
136.66.57.241 - - [05/Sep/2026:20:27:24 +0000] "GET /database.sql HTTP/1.1" 404 4361 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
136.66.57.241 - - [05/Sep/2026:20:27:24 +0000] "GET /backup.tar.gz HTTP/1.1" 404 4360 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
136.66.57.241 - - [05/Sep/2026:20:27:24 +0000] "GET /dump.sql HTTP/1.1" 404 4360 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
136.66.57.241 - - [05/Sep/2026:20:27:24 +0000] "GET /archive.zip HTTP/1.1" 404 4362 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
136.66.57.241 - - [05/Sep/2026:20:27:24 +0000] "GET /public_html.zip HTTP/1.1" 404 4360 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
136.66.57.241 - - [05/Sep/2026:20:27:24 +0000] "GET /bac
...
show less
Brute-Force
🇫🇷
dynamix
2026-09-04 15:07:08
(1 day ago)
Multiple WAF Violations
Web App Attack