🇳🇱
homeshowdomain.nl
2026-09-08 22:04:00
(9 hours ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇧🇪
cmbplf
2026-09-08 21:37:16
(9 hours ago)
400 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:03:53
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:03:47.233138 2026] [security2:error] [pid 26542:tid 26542] [client 136.85.86.197:55266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chadfishman.com"] [uri "/@fs/app/.env"] [unique_id "aqBqI5MIBH-4YP9MoEwLIgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:35:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:35:26.484748 2026] [security2:error] [pid 10417:tid 10417] [client 136.85.86.197:8050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jimpaddywilliams.org"] [uri "/@fs/.env"] [unique_id "aqBjft_17OymBGZrfRzf6QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 19:27:51
(11 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 18:30:31
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:30:27.045888 2026] [security2:error] [pid 19454:tid 19454] [client 136.85.86.197:32428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prototype.warnock.ws"] [uri "/@fs/.env"] [unique_id "aqBUQ0YVyUjZK6D7TBrlZQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:05:51
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:05:45.270433 2026] [security2:error] [pid 25271:tid 25271] [client 136.85.86.197:8404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fagerbergfamily.net"] [uri "/@fs/src/.env"] [unique_id "aqBOeQSSqJrdgSJzmgg4SAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 17:55:15
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
gadix
2026-09-08 17:53:28
(13 hours ago)
[08/Sep/2026:19:53:26.821453 +0200] aqBLlqo2cQ-Bc42S8prXVwAAAJg 136.85.86.197 56404 127.0.0.1 7081
[ ...
show more
[08/Sep/2026:19:53:26.821453 +0200] aqBLlqo2cQ-Bc42S8prXVwAAAJg 136.85.86.197 56404 127.0.0.1 7081
[08/Sep/2026:19:53:26.825092 +0200] aqBLlqo2cQ-Bc42S8prXWQAAAIA 136.85.86.197 56408 127.0.0.1 7081
[08/Sep/2026:19:53:26.826779 +0200] aqBLlqo2cQ-Bc42S8prXWgAAAIE 136.85.86.197 56416 127.0.0.1 7081
...
show less
Web App Attack
🇬🇧
consul.to
2026-09-08 17:43:47
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇵🇱
TaKeN
2026-09-08 17:19:56
(13 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 2 matching blocked event(s) between 2026-09-08T19:19:56+02:00 and 2026-09-08T19:19:56+02:00. Sample requested paths: /@fs/.env.production, /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ.
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 17:15:32
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:15:28.662828 2026] [security2:error] [pid 28407:tid 28407] [client 136.85.86.197:15966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.arcadiapropertiesllc.com"] [uri "/@fs/app/.env"] [unique_id "aqBCsKDE6lleUQezV-4zyQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-08 17:07:41
(14 hours ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 16:36:17
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.197 (197.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:36:10.632285 2026] [security2:error] [pid 22902:tid 22902] [client 136.85.86.197:16284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sixsensehealing.com"] [uri "/@fs/root/.env"] [unique_id "aqA5elnMH9XG4YnahF5VsAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Omar Martínez
2026-09-08 16:26:56
(14 hours ago)
[Tue Sep 08 10:26:33.162302 2026] [core:error] [pid 2927576:tid 139864083240512] [client 136.85.86.1 ...
show more
[Tue Sep 08 10:26:33.162302 2026] [core:error] [pid 2927576:tid 139864083240512] [client 136.85.86.197:31184] AH10244: invalid URI path (/@fs/../../.env?raw??)
[Tue Sep 08 10:26:54.257157 2026] [core:error] [pid 2965413:tid 139864594966080] [client 136.85.86.197:53276] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??)
...
show less
Phishing
Email Spam
Blog Spam