๐ณ๐ฑ
Site.eu
2026-10-10 13:21:43
(7 hours ago)
Excessive multi-domain requests
Brute-Force
๐จ๐ฑ
Fernando Soto
2026-10-10 03:05:25
(18 hours ago)
WAF propio vps1 (CL): 404x13,sensx89 score 22 en 1h. sondeo rutas sensibles, barrido 404.
Port Scan
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-09 21:59:54
(23 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-08.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-09 05:54:06
(1 day ago)
2026/10/09 06:54:04 [error] 4060693#4060693: *1427963 access forbidden by rule, client: 136.90.91.23 ...
show more
2026/10/09 06:54:04 [error] 4060693#4060693: *1427963 access forbidden by rule, client: 136.90.91.236, server: vp-arc.org, request: "GET /_nuxt/../.env HTTP/2.0", host: "vp-arc.org"
2026/10/09 06:54:04 [error] 4060693#4060693: *1427963 access forbidden by rule, client: 136.90.91.236, server: vp-arc.org, request: "GET /api/data/..%2f..%2f.env HTTP/2.0", host: "vp-arc.org"
2026/10/09 06:54:04 [error] 4060693#4060693: *1427963 access forbidden by rule, client: 136.90.91.236, server: vp-arc.org, request: "GET /api/orders/..%2f..%2f.env HTTP/2.0", host: "vp-arc.org"
show less
Brute-Force
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-10-09 05:51:06
(1 day ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex:/^\/\.env/i
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 05:28:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.90.91.236 (236.91.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.91.236 (236.91.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:28:23.686403 2026] [security2:error] [pid 12826:tid 12826] [client 136.90.91.236:46278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "russiacoin.info"] [uri "/api/console/api_server"] [unique_id "ash7d6eu6sZgqomyLZ_MDQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:14:57
(1 day ago)
147 attacks on env grabbing URLs (type 2), password/key grabbing URLs, directory traversals, PHP URL ...
show more
147 attacks on env grabbing URLs (type 2), password/key grabbing URLs, directory traversals, PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs, shell probes:
GET /userfiles?path=../../../../proc/self/environ HTTP/1.1
GET /.git-credentials HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /secrets.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /core/.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
show less
Hacking
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-10-09 05:10:26
(1 day ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-09 05:06:02
(1 day ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [ice01]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:59:26
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.90.91.236 (236.91.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.91.236 (236.91.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:59:19.086731 2026] [security2:error] [pid 32275:tid 32275] [client 136.90.91.236:37616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelward.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelward.com"] [uri "/z9x8c7v6b5-debug-trigger-michaelward.com"] [unique_id "ash0p0SPwR8qeJo9FWGllwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:43:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.90.91.236 (236.91.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.91.236 (236.91.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:43:46.549840 2026] [security2:error] [pid 24160:tid 24160] [client 136.90.91.236:58852] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jbcllcnet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jbcllcnet.com"] [uri "/z9x8c7v6b5-debug-trigger-jbcllcnet.com"] [unique_id "ashxAiEgCsPb9PS3ENwEJwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:27:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.90.91.236 (236.91.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.91.236 (236.91.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:27:47.415136 2026] [security2:error] [pid 8322:tid 8322] [client 136.90.91.236:34414] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gabosoftware.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gabosoftware.com"] [uri "/z9x8c7v6b5-debug-trigger-gabosoftware.com"] [unique_id "ashtQyYLNKYqlfi-OcEjygAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-09 04:24:03
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1248
Exploited Host
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-09 04:23:08
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
security.rdmc.fr
2026-10-09 04:20:33
(1 day ago)
Web App Attack
Web App Attack