🇺🇸
TPI-Abuse
2026-09-04 15:20:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:38.274812 2026] [security2:error] [pid 5690:tid 5690] [client 136.66.70.233:37736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mrbaystreet.com"] [uri "/.env.prod"] [unique_id "aprhxsaW_OP89h-U9upRywAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-09-04 14:55:09
(2 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-04 13:15:03
(3 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:35:15
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.66.70.233 (233.70.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 136.66.70.233 (233.70.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:35:10.966778 2026] [security2:error] [pid 13538:tid 13538] [client 136.66.70.233:42838] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ftp.experimentalscene.com"] [uri "/.env.dev"] [unique_id "apq6_oSYGgu6-P4GQaRI4gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:33:45
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 12:18:10
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:18:03.364372 2026] [security2:error] [pid 5251:tid 5251] [client 136.66.70.233:36234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindheartbreath.com"] [uri "/wp-config.php.bak"] [unique_id "apq2-wbWtNlucPjPFUJvhgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:16:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:30.641733 2026] [security2:error] [pid 19861:tid 19861] [client 136.66.70.233:33706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cp.graner.us"] [uri "/.env.backup"] [unique_id "apqojkN1oB76MQbB-XEzxQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:59:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:59:40.863719 2026] [security2:error] [pid 24676:tid 24676] [client 136.66.70.233:51020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bizecomm.net"] [uri "/.env"] [unique_id "apqknHJ8-PcPr9TkMVP2gwAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:50:04
(6 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇫🇷
mail.avx.gr
2026-09-04 10:43:42
(6 hours ago)
(nginxENVSCAN) nginx environment-file scanner detected from 136.66.70.233 (US/United States/Oregon/T ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 136.66.70.233 (US/United States/Oregon/The Dalles/233.70.66.136.bc.googleusercontent.com)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:42:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:42:36.525879 2026] [security2:error] [pid 4689:tid 4704] [client 136.66.70.233:33702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lapulperiagirona.com"] [uri "/wp-config.php~"] [unique_id "apqgnL4lvAgpmFrx0QPQawAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 10:24:07
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
LRob
2026-09-04 10:12:59
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.backup (+10 more) | 2026-09-04 10:12 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:01:24
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.70.233 (233.70.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:01:18.612483 2026] [security2:error] [pid 8958:tid 8958] [client 136.66.70.233:57826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bigheartskitchen.net"] [uri "/.env"] [unique_id "apqW7klC9BfzdIDGARBZDgAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
sockominfo
2026-09-04 10:00:29
(7 hours ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Email Spam