🇺🇸
TPI-Abuse
2026-09-17 05:39:03
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 136.67.214.14 (14.214.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.214.14 (14.214.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:38:59.171025 2026] [security2:error] [pid 3981:tid 3998] [client 136.67.214.14:52704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seracon.com.ec"] [uri "/.git/config"] [unique_id "aqt88zku9LJ-mMHW4ho8DQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
spongebob1234
2026-09-17 05:23:16
(17 minutes ago)
Wazuh SIEM: 10 tentative(s) d'accès suspecte(s) / non autorisée(s) détectée(s). Type(s) d'attaque : ...
show more
Wazuh SIEM: 10 tentative(s) d'accès suspecte(s) / non autorisée(s) détectée(s). Type(s) d'attaque : Web (Erreur 400 Bad Request), Web (Erreur 403 Interdit), Web (Erreur 404 Non Trouvé).
show less
Hacking
Bad Web Bot
Web App Attack
🇩🇰
HostingGroup
2026-09-17 05:01:55
(38 minutes ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 3. First blocked: 2026-09-17.
show less
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-17 04:32:46
(1 hour ago)
Many_bad_calls
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-17 04:08:26
(1 hour ago)
Scanning for web/db/file exploits on www.pcdiscounter.nl
SQL Injection
Bad Web Bot
Web App Attack
🇪🇸
robotstxt
2026-09-17 04:07:18
(1 hour ago)
136.67.214.14 - - [17/Sep/2026:04:07:01 +0000] "GET /ml/.env HTTP/2.0" 403 27035 "-" "Mozilla/5.0 (c ...
show more
136.67.214.14 - - [17/Sep/2026:04:07:01 +0000] "GET /ml/.env HTTP/2.0" 403 27035 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="136.67.214.14"
136.67.214.14 - - [17/Sep/2026:04:07:01 +0000] "GET /pipeline/.env HTTP/2.0" 403 27057 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-" edge="136.67.214.14"
136.67.214.14 - - [17/Sep/2026:04:07:02 +0000] "GET /data/.env HTTP/2.0" 403 27032 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="136.67.214.14"
136.67.214.14 - - [17/Sep/2026:04:07:02 +0000] "GET /model/.env HTTP/2.0" 403 27033 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="136.67.214.14"
136.67.214.14 - - [17/Sep/2026:04:07:02 +0000] "GET /build/manifest.json HTTP/2.0" 403 25751 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="136.67.214.14"
...
show less
Web App Attack
🇳🇱
Savvii
2026-09-17 04:00:08
(1 hour ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
abuse-opdc
2026-09-17 03:55:45
(1 hour ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
🇳🇱
debestelapp
2026-09-17 03:50:14
(1 hour ago)
Web App Attack
🇳🇱
Savvii
2026-09-17 03:18:24
(2 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-17 03:10:39
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 02:06:37
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.214.14 (14.214.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.214.14 (14.214.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:06:31.404775 2026] [security2:error] [pid 22158:tid 22158] [client 136.67.214.14:37476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lukeschicago.com"] [uri "/.github/.env"] [unique_id "aqtLJ3TsWek5VqgD02PeHgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 01:40:12
(4 hours ago)
Bot / seems abusive / Apache connections: 21
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-17 01:19:10
(4 hours ago)
Try to access /pkg/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 01:18:17
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.67.214.14 (14.214.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.67.214.14 (14.214.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:18:14.150837 2026] [security2:error] [pid 14131:tid 14131] [client 136.67.214.14:37966] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kittencream.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kittencream.com"] [uri "/rclone.conf"] [unique_id "aqs_1rk5hSJoX499OYOjcAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack