🇫🇷
masterguru
2026-09-07 00:56:07
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:27:03
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.17.57 (57.17.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.17.57 (57.17.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:26:57.210808 2026] [security2:error] [pid 14397:tid 14397] [client 136.85.17.57:47782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pulleasy.com"] [uri "/.env.local"] [unique_id "ap4E0SI3P4en6rfR0wcLAgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 22:05:52
(7 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
homeshowdomain.nl
2026-09-06 22:02:07
(7 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇪🇸
alferez
2026-09-06 20:47:59
(8 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:26:58
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.17.57 (57.17.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.17.57 (57.17.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:26:54.228126 2026] [security2:error] [pid 9483:tid 9483] [client 136.85.17.57:56112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.accu-tuner.com"] [uri "/@fs/../.env"] [unique_id "ap3MjlS80Rnq6DTUoTfavgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
tentwentyfour
2026-09-06 20:03:33
(9 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:55:58
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.85.17.57 (57.17.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.17.57 (57.17.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:55:54.665182 2026] [security2:error] [pid 654780:tid 654780] [client 136.85.17.57:51724] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kittysalterations.com|F|2"] [data ".kittysalterations.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kittysalterations.com"] [uri "/z9x8c7v6b5-debug-trigger-www.kittysalterations.com"] [unique_id "ap3FSh2lrKvYxR72-EgqxAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 19:31:29
(9 hours ago)
20 attempts against mh_ha-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 19:05:37
(10 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:43:27
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.17.57 (57.17.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.17.57 (57.17.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:43:19.894093 2026] [security2:error] [pid 28639:tid 28639] [client 136.85.17.57:35540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stelaware.com"] [uri "/.env.production"] [unique_id "ap2mN_DkP9vkKjEIGmqDlQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 17:21:53
(12 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇨🇦
Anytech
2026-09-06 17:01:11
(12 hours ago)
Blocked by ConnMonitor
Web App Attack
🇫🇷
Octopuce
2026-09-06 17:00:25
(12 hours ago)
Aggressive web search of vulnerable pages: /@fs/src/.env?raw?? /@fs/app/.env?raw?? /@fs/..%252f..%25 ...
show more
Aggressive web search of vulnerable pages: /@fs/src/.env?raw?? /@fs/app/.env?raw?? /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? /_nu ...
show less
Web App Attack
🇬🇧
consul.to
2026-09-06 16:46:56
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack