๐บ๐ธ
mw
2026-08-27 00:00:31
(1 hour ago)
GET /files../etc/passwd HTTP/1.1
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-26 21:59:46
(3 hours ago)
Auto-ban: >3000 req/min op 2026-08-26
Web App Attack
SSH
Hacking
Anonymous
2026-08-26 17:15:43
(8 hours ago)
Attempted search for exploits and vulnerabilities detected by fail2ban
...
Port Scan
Brute-Force
๐ฉ๐ช
akasolutions.de
2026-08-26 16:29:07
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.66.76.42 (US/United States/42.76.66 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.66.76.42 (US/United States/42.76.66.136.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
masterguru
2026-08-26 16:27:11
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐จ๐ญ
zynex
2026-08-26 16:14:24
(9 hours ago)
URL Probing: /.env
Web App Attack
๐ช๐ธ
alferez
2026-08-26 16:02:57
(9 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 14:48:26
(11 hours ago)
(mod_security) mod_security (id:211190) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:211190) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:48:20.183540 2026] [security2:error] [pid 26017:tid 26039] [client 136.66.76.42:1618] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.yubasutterphotography.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.yubasutterphotography.com"] [uri "/"] [unique_id "ao78tJ4DH60-QkDR2QM0dQAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-26 14:18:34
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 12:35:29
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:35:23.536302 2026] [security2:error] [pid 26097:tid 26097] [client 136.66.76.42:37516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gooch-excavation.com"] [uri "/static../.env"] [unique_id "ao7di-kk4rvT9yZwTo5ERgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 11:50:12
(14 hours ago)
Bot / seems abusive / Apache connections: 103
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 11:33:14
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:33:06.382247 2026] [security2:error] [pid 9318:tid 9318] [client 136.66.76.42:20982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imerka.com.mx"] [uri "/static../.env"] [unique_id "ao7O8k3-qNHpuZQKBAaIygAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 11:02:37
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:02:32.424302 2026] [security2:error] [pid 17265:tid 17265] [client 136.66.76.42:43062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nutandboltguy.com"] [uri "/.env.local.php"] [unique_id "ao7HyGiUdYrj07GSVlf9mwAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-26 10:20:26
(15 hours ago)
Aggressive web search of vulnerable pages: /media../.env /.env.local /app/.env /api/.env /backend/.e ...
show more
Aggressive web search of vulnerable pages: /media../.env /.env.local /app/.env /api/.env /backend/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:52:54
(16 hours ago)
(mod_security) mod_security (id:211190) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:211190) triggered by 136.66.76.42 (42.76.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:52:46.556330 2026] [security2:error] [pid 6061:tid 6061] [client 136.66.76.42:11412] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||calentadoresdemexico.com.mx|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /download?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calentadoresdemexico.com.mx"] [uri "/download"] [unique_id "ao63blN3MAm4klFV5RT9gAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack