🇳🇱
homeshowdomain.nl
2026-09-07 22:01:06
(10 minutes ago)
Auto-ban: >3000 req/min op 2026-09-07
Web App Attack
SSH
Hacking
🇨🇭
backslash
2026-09-07 21:03:00
(1 hour ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 20:39:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:39:45.291846 2026] [security2:error] [pid 24680:tid 24680] [client 136.70.87.4:46574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.newsfromearth.banis-associates.com"] [uri "/@fs/../.env"] [unique_id "ap8hEWYVqyT9s6lv0prxpAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 20:35:20
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:47:17
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:47:09.681372 2026] [security2:error] [pid 21589:tid 21589] [client 136.70.87.4:58070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.danged.com"] [uri "/@fs/.env"] [unique_id "ap8GrfvEUBhjq8FVFInrtwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
maxxsense
2026-09-07 18:17:53
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.70.87.4 (US/United States/4.87.70.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.70.87.4 (US/United States/4.87.70.136.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-07 17:59:07
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 17:53:25
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:53:22.108618 2026] [security2:error] [pid 5832:tid 5832] [client 136.70.87.4:9486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.khaoula.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap76EsJdWJsgJNtjUEtcwwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 17:39:30
(4 hours ago)
373 requests with url.path *credentials.json
356 requests with url.path *.azure/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-07 17:23:58
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:49:58
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:49:52.368215 2026] [security2:error] [pid 13894:tid 13894] [client 136.70.87.4:19400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fathereeinc.com"] [uri "/@fs/src/.env"] [unique_id "ap7rMC3gjjry_3Xs4vsb0wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 16:49:44
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇮🇹
VHosting
2026-09-07 16:40:03
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-07 16:28:15
(5 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 16:18:34
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.87.4 (4.87.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:18:26.170675 2026] [security2:error] [pid 17432:tid 17432] [client 136.70.87.4:45178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.goldenstatealliance.com"] [uri "/@fs/../../.env"] [unique_id "ap7j0u21vVUfHDC44ZGslwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack