🇫🇷
Octopuce
2026-09-10 09:33:42
(5 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇫🇷
spot
2026-09-10 06:02:45
(9 hours ago)
136.83.4.12 - - [10/Sep/2026:07:02:44 +0100] "GET /.git/config HTTP/1.1" 404 543 "-" "Mozilla/5.0 (W ...
show more
136.83.4.12 - - [10/Sep/2026:07:02:44 +0100] "GET /.git/config HTTP/1.1" 404 543 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
🇵🇱
sefinek.net
2026-09-10 01:05:04
(14 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /hosting/phpinfo.php | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-10 00:06:47
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.83.4.12 (12.4.83.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.83.4.12 (12.4.83.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 20:06:42.648400 2026] [security2:error] [pid 27796:tid 27796] [client 136.83.4.12:37332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "snickerifabrik.com"] [uri "/.git/config"] [unique_id "aqH0kgzH_lEiYJLaj_daVQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
snhosting
2026-09-09 22:29:15
(16 hours ago)
136.83.4.12 - - [10/Sep/2026:00:29:05 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 ( ...
show more
136.83.4.12 - - [10/Sep/2026:00:29:05 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.83.4.12 - - [10/Sep/2026:00:29:06 +0200] "GET /.env HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.83.4.12 - - [10/Sep/2026:00:29:06 +0200] "GET /.env.local HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.83.4.12 - - [10/Sep/2026:00:29:06 +0200] "GET /.env.production HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.83.4.12 - - [10/Sep/2026:00:29:06 +0200] "GET /.env.staging HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
🇳🇱
homeshowdomain.nl
2026-09-09 21:59:28
(17 hours ago)
Auto-ban: >3000 req/min op 2026-09-09
Web App Attack
SSH
Hacking
Anonymous
2026-09-09 21:24:06
(18 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-09 21:14:58
(18 hours ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-09 18:44:00
(20 hours ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
debestelapp
2026-09-09 18:05:13
(21 hours ago)
Web App Attack
Anonymous
2026-09-09 16:59:04
(22 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇧🇾
lns.bz
2026-09-09 16:46:55
(22 hours ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-09-09 12:30:04
(1 day ago)
[Wed Sep 09 12:30:01.929427 2026] [security2:error] [pid 506412:tid 506412] [client 136.83.4.12:3990 ...
show more
[Wed Sep 09 12:30:01.929427 2026] [security2:error] [pid 506412:tid 506412] [client 136.83.4.12:39906] [client 136.83.4.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "lithomessiniaki.gr"] [uri "/.env.bak"] [unique_id "aqFRSQJLEpMvgoZXX3oH3wAAAAs"]
[Wed Sep 09 12:30:02.424352 2026] [security2:error] [pid 504585:tid 504585] [client 136.83.4.12:39922] [client 136.83.4.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [seve
...
show less
Web App Attack