🇧🇾
lns.bz
2026-09-06 06:05:11
(12 hours ago)
Too many 404 requests [BY]
Web App Attack
🇫🇷
Catalin Negru
2026-09-06 03:55:10
(14 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 03:26:23
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:26:16.905912 2026] [security2:error] [pid 22022:tid 22022] [client 136.108.3.169:45994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christmaspartynapkins.com"] [uri "/.env.backup"] [unique_id "apzdWP9uoCT6k3MIakwHUwAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Gabriel Camargo
2026-09-06 02:01:59
(16 hours ago)
136.108.3.169 - - [05/Sep/2026:21:01:58 -0500] "GET /.env.local HTTP/1.1" 301 178 "-" "crusader-work ...
show more
136.108.3.169 - - [05/Sep/2026:21:01:58 -0500] "GET /.env.local HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
136.108.3.169 - - [05/Sep/2026:21:01:58 -0500] "GET /.env HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
136.108.3.169 - - [05/Sep/2026:21:01:58 -0500] "GET /.env.production HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 00:01:45
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:01:39.135303 2026] [security2:error] [pid 21817:tid 21817] [client 136.108.3.169:56990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessicalevant.com"] [uri "/.env.production"] [unique_id "apytY9po_dwI_aSwkTSkQgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-05 23:46:39
(19 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, actuator, config_backup, source_backup, ignition_debug. Observed by 1 sensor(s); 26 hits.
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 23:26:27
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:22:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:22:40.624775 2026] [security2:error] [pid 8347:tid 8347] [client 136.108.3.169:54798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lexvaz.com"] [uri "/.env.local"] [unique_id "apykQLtoyKy3vvBPbsJeOAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:56:22
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:56:15.648706 2026] [security2:error] [pid 26422:tid 26422] [client 136.108.3.169:48154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.qed-consulting.co"] [uri "/wp-config.php.bak"] [unique_id "apyeD_21iKjgjRSsO-bL1QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-05 22:41:11
(20 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:29:30
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.3.169 (169.3.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:29:21.980814 2026] [security2:error] [pid 31497:tid 31497] [client 136.108.3.169:60940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brunerdevelopment.com"] [uri "/.env"] [unique_id "apyXwVHjWoF6BODij5JLsgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:24:01
(20 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-09-05 22:05:55
(20 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-05 21:47:18
(21 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.108.3.169 (US/United States/169.3.108.13 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.108.3.169 (US/United States/169.3.108.136.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.108.3.169 - - [05/Sep/2026:23:47:14 +0200] "GET /.aider.env HTTP/1.1" 406 4831 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
136.108.3.169 - - [05/Sep/2026:23:47:14 +0200] "GET /.aider.conf.yml HTTP/1.1" 404 4890 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
136.108.3.169 - - [05/Sep/2026:23:47:14 +0200] "GET /.aider.model.settings.yml HTTP/1.1" 404 4892 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
show less
Port Scan
Anonymous
2026-09-05 21:22:27
(21 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking