🇺🇸
BenTahily
2026-09-09 07:00:43
(1 hour ago)
Malicious activity against marketblitzer.com (BLITZER Trading Platform)
Web App Attack
Hacking
🇺🇸
BenTahily
2026-09-08 07:00:43
(1 day ago)
Malicious activity against marketblitzer.com (BLITZER Trading Platform)
Web App Attack
Hacking
🇺🇸
BenTahily
2026-09-07 07:00:03
(2 days ago)
Malicious activity against marketblitzer.com (BLITZER Trading Platform)
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-05 22:02:37
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇧🇪
taivas.nl
2026-09-05 04:33:21
(4 days ago)
Many_bad_calls
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:49
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇫🇷
LRob
2026-09-04 17:21:12
(4 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /@fs/app/.env | 2026-09-04 17:21 UTC
show less
Hacking
Web App Attack
🇩🇪
bazter.pro
2026-09-04 15:21:11
(4 days ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:23:23
(4 days ago)
Scraping for .env file
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:09:06
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:09:01.793441 2026] [security2:error] [pid 758:tid 758] [client 136.70.113.44:49740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coolray.net"] [uri "/@fs/.env"] [unique_id "aprC7dHNMKGkbEK5G7XYAAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:25:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:24:58.826437 2026] [security2:error] [pid 28112:tid 28112] [client 136.70.113.44:48542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidsonmanagement.net"] [uri "/@fs/app/.env"] [unique_id "apq4mu4wMmcUy_BGIRyX2AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
D3monite
2026-09-04 11:40:37
(4 days ago)
Attempted Brute Force (APIService)
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 10:22:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:22:27.231371 2026] [security2:error] [pid 7454:tid 7454] [client 136.70.113.44:21172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fgrotary.org"] [uri "/@fs/.env.staging"] [unique_id "apqb41OBGsyswMwmQqSgtgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:50:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:50:47.559541 2026] [security2:error] [pid 6129:tid 6129] [client 136.70.113.44:29606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cageliners.net"] [uri "/@fs/.env"] [unique_id "apqUd-GcVdjAXRqoSWRjKAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:43:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.113.44 (44.113.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:43:22.380709 2026] [security2:error] [pid 16013:tid 16013] [client 136.70.113.44:24988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dmasoftlab.com"] [uri "/@fs/.env"] [unique_id "appoigfoAszuw1Vv_hM7WQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack