🇺🇸
TPI-Abuse
2026-09-07 18:37:31
(24 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:37:23.984604 2026] [security2:error] [pid 15175:tid 15175] [client 136.66.63.76:19738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rendermatrix.com"] [uri "/@fs/root/.env"] [unique_id "ap8EY9xjmoGDe61PskVH4QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 18:00:16
(1 hour ago)
Aggressive web search of vulnerable pages: /.docker/.env /images../.env /v2/.env /_nuxt/../.env /.en ...
show more
Aggressive web search of vulnerable pages: /.docker/.env /images../.env /v2/.env /_nuxt/../.env /.env.local ...
show less
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 18:00:06
(1 hour ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇨🇦
Dunham Support
2026-09-07 17:37:37
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 136.66.63.76 (US/United States/76.63.66 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.66.63.76 (US/United States/76.63.66.136.bc.googleusercontent.com)
show less
SQL Injection
🇨🇭
backslash
2026-09-07 17:36:00
(1 hour ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
🇷🇴
clauss
2026-09-07 17:34:41
(1 hour ago)
136.66.63.76 - - [07/Sep/2026:20:34:40 +0300] "GET /@fs/home/ubuntu/.anthropic/config.json?raw?? HTT ...
show more
136.66.63.76 - - [07/Sep/2026:20:34:40 +0300] "GET /@fs/home/ubuntu/.anthropic/config.json?raw?? HTTP/2.0" 404 13365 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots)"
136.66.63.76 - - [07/Sep/2026:20:34:41 +0300] "GET /@fs/root/.anthropic/config.json?raw?? HTTP/2.0" 404 13365 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:26:18
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:26:11.356607 2026] [security2:error] [pid 30355:tid 30355] [client 136.66.63.76:28176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.personalizedweddingnapkins.net"] [uri "/@fs/.env"] [unique_id "ap7zs13pEK9jKW1XHNDZ6wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:47:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:47:04.734920 2026] [security2:error] [pid 25788:tid 25788] [client 136.66.63.76:51188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emilybaotrannguyen.com"] [uri "/@fs/.env"] [unique_id "ap7qiKGu_60cy8l4RX74bgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-07 16:25:45
(2 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:16:22
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:16:13.058461 2026] [security2:error] [pid 25364:tid 25364] [client 136.66.63.76:24880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kingdom-way.org"] [uri "/@fs/.env.production"] [unique_id "ap7jTTah7rluYi9v1kkgLgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 16:00:05
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 15:56:17
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.76 (76.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:56:13.546009 2026] [security2:error] [pid 9881:tid 9881] [client 136.66.63.76:40296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.texaspropertyinspection.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap7enbRMvieZas54ZXdHzAAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack