🇳🇱
homeshowdomain.nl
2026-09-06 21:59:55
(22 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇩🇪
TheDjRider
2026-09-06 16:57:26
(1 day ago)
Web reconnaissance or vulnerability scan detected.
Detection: Fail2Ban (apache-backup-scanner).
Serv ...
show more
Web reconnaissance or vulnerability scan detected.
Detection: Fail2Ban (apache-backup-scanner).
Service: Web server.
Ban duration: unknown.
Time (UTC): 2026-09-06T16:57:25Z. Evidence: REDACTED_IP - - [06/Sep/2026:16:57:25 +0000] "GET /backup.tar HTTP/1.1" 403 4390 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" REDACTED_IP - -
show less
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-06 06:08:00
(1 day ago)
Fail2Ban - [NGINX]Malicious request blocked on nginx-444 ... [ice01,ice02,wa01,wa02]
Hacking
Bad Web Bot
🇫🇷
Catalin Negru
2026-09-06 06:04:27
(1 day ago)
2026-09-06 09:04:26,584 fail2ban.actions [1796604]: NOTICE [laravel-env] Ban 136.107.14.229
...
show more
2026-09-06 09:04:26,584 fail2ban.actions [1796604]: NOTICE [laravel-env] Ban 136.107.14.229
2026-09-06 09:04:26,631 fail2ban.actions [1796604]: NOTICE [apache-dirscan] Ban 136.107.14.229
2026-09-06 09:04:26,672 fail2ban.actions [1796604]: NOTICE [apache-scan] Ban 136.107.14.229
2026-09-06 09:04:26,738 fail2ban.actions [1796604]: NOTICE [apache-404] Ban 136.107.14.229
2026-09-06 09:04:26,842 fail2ban.actions [1796604]: NOTICE [laravel-auth] Ban 136.107.14.229
...
show less
Brute-Force
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-06 04:07:02
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:49:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.107.14.229 (229.14.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.14.229 (229.14.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:29.785397 2026] [security2:error] [pid 257599:tid 257631] [client 136.107.14.229:50460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.priyom.us"] [uri "/.env.prod"] [unique_id "apziyR6CKJg02Y_H8XxcRwAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:36:50
(1 day ago)
[da.kdns.gr] httpd-config-scan: sites=www.pnoimitrotitas.gr; logs=/var/log/httpd/domains/pnoimitroti ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.pnoimitrotitas.gr; logs=/var/log/httpd/domains/pnoimitrotitas.gr.log; samples=/.env.dev | /wp-config.php.swp | /wp-config.php.bak
show less
Hacking
Web App Attack
🇺🇸
Lee Daniel
2026-09-06 03:30:51
(1 day ago)
136.107.14.229 - - [05/Sep/2026:23:30:50 -0400] "GET /.env HTTP/1.1" 403 6236 "-" "crusader-worker/1 ...
show more
136.107.14.229 - - [05/Sep/2026:23:30:50 -0400] "GET /.env HTTP/1.1" 403 6236 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:24:29
(1 day ago)
Aggressive web scan
Web App Attack
🇩🇪
dispaisyenterprises
2026-09-06 03:20:29
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpo ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /wp-config.php.bak | UA: crusader-worker/1.0 • Reported by DisPaisy Enterprises (dispaisy.systems)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 02:58:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.107.14.229 (229.14.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.14.229 (229.14.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:46.043940 2026] [security2:error] [pid 7387:tid 7387] [client 136.107.14.229:57596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jackkerrart.com"] [uri "/.env.production"] [unique_id "apzW5sv9YsQ7qJfFUkxGcwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-06 02:56:28
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-06 02:26:09
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:18:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.107.14.229 (229.14.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.14.229 (229.14.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:18:11.890795 2026] [security2:error] [pid 12496:tid 12496] [client 136.107.14.229:45640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tdj.franchiseconsultants.org"] [uri "/.env.bak"] [unique_id "apzNY64RIOXjDTJy6Onr2AAAAHY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-06 01:39:07
(1 day ago)
[06/Sep/2026:04:39:07 +0300] -- 136.107.14.229 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[06/Sep/2026:04:39:07 +0300] -- 136.107.14.229 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack