🇫🇷
dynamix
2026-09-09 04:24:02
(17 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:21:51
(20 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:21:46.281882 2026] [security2:error] [pid 1303:tid 1303] [client 136.70.80.125:3964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.buccinet.com"] [uri "/@fs/src/.env"] [unique_id "aqDe2t3CLBQ1uHdr7KgzbAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 03:47:36
(54 minutes ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:47:35
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:47:31.964160 2026] [security2:error] [pid 5320:tid 5320] [client 136.70.80.125:44768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.philipjnielsen-drafting-design.com"] [uri "/@fs/.env.local"] [unique_id "aqDW0-shRIdG6Az86zzVmQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 03:12:06
(1 hour ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:00:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:00:25.195623 2026] [security2:error] [pid 21014:tid 21014] [client 136.70.80.125:55268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.badwaterclaims.com"] [uri "/@fs/.env.local"] [unique_id "aqDLyTsZYNC0qSy95ZXtVgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 02:45:02
(1 hour ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:16:03
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:15:58.285103 2026] [security2:error] [pid 20585:tid 20585] [client 136.70.80.125:56466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kittencream.com"] [uri "/@fs/../../.env"] [unique_id "aqDBXvagF1Dedast-kJfLgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-09 02:09:26
(2 hours ago)
Aggressive web search of vulnerable pages: /v1/.env /_nuxt/../.env /.env.local /v2/.env /.env ...
Web App Attack
🇳🇱
e.fierstra
2026-09-09 02:02:21
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-09 01:27:12
(3 hours ago)
1.858 requests with url.path *.env
678 requests with url.path *.aws/*
551 requests with url.path ...
show more
1.858 requests with url.path *.env
678 requests with url.path *.aws/*
551 requests with url.path *credentials.json
482 requests with url.path *config.json
209 requests with url.path */proc/*
138 requests with url.path *.php.bak
122 requests with url.path */auth.json
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 01:26:36
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.80.125 (125.80.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:26:28.389641 2026] [security2:error] [pid 13928:tid 13928] [client 136.70.80.125:21154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lancehancock.com"] [uri "/@fs/../../.env"] [unique_id "aqC1xNbgBsiP5L9MCob-HQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-09 00:55:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-09 00:47:46
(3 hours ago)
Excessive 404/403 errors
Brute-Force
🇩🇪
todix
2026-09-09 00:45:18
(3 hours ago)
Web App Attack Exploid from 136.70.80.125
Web App Attack