๐ฉ๐ช
kkeyser
2026-08-27 18:45:13
(29 minutes ago)
GET /.env HTTP/1.1
Web App Attack
๐บ๐ธ
CBJ
2026-08-27 18:41:38
(32 minutes ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐จ๐ญ
zynex
2026-08-27 17:48:58
(1 hour ago)
URL Probing: /wp-config.php.bak
Web App Attack
๐ฉ๐ช
maxpower
2026-08-27 17:33:31
(1 hour ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.108.44.92 (US/United States/92.44.10 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.108.44.92 (US/United States/92.44.108.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.108.44.92 - - [27/Aug/2026:19:33:27 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=mail.effegroup.eu
show less
Port Scan
๐ฎ๐ช
AutosOnShow
2026-08-27 17:10:07
(2 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-08-27 17:09:48.212 |
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-27 17:09:59
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฎ๐น
Inartis
2026-08-27 16:56:40
(2 hours ago)
136.108.44.92 - - [27/Aug/2026:18:56:39 +0200] "GET /.env.local HTTP/1.1" 403 5515 "-" "crusader-wor ...
show more
136.108.44.92 - - [27/Aug/2026:18:56:39 +0200] "GET /.env.local HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
136.108.44.92 - - [27/Aug/2026:18:56:39 +0200] "GET /.env.production HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
136.108.44.92 - - [27/Aug/2026:18:56:39 +0200] "GET /.env.dev HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:39:40
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.44.92 (92.44.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.44.92 (92.44.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:39:34.250167 2026] [security2:error] [pid 11899:tid 11899] [client 136.108.44.92:53016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "files.jeremyscraig.com"] [uri "/.env.production"] [unique_id "apBoRkdQcj4eO4kUaSY2EAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 16:10:02
(3 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:44:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.44.92 (92.44.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.44.92 (92.44.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:44:36.179450 2026] [security2:error] [pid 25036:tid 25066] [client 136.108.44.92:59788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.selfhelpbook.aafm.us"] [uri "/.env"] [unique_id "apBbZHTMLL-Fd9id-UVU1QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 15:35:03
(3 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
factor1
2026-08-27 13:47:30
(5 hours ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐บ๐ธ
Sling
2026-08-27 13:13:57
(6 hours ago)
Automated detection: IP accessed 9 sensitive endpoints within 30s on u1.slingexe.com. Paths: /storag ...
show more
Automated detection: IP accessed 9 sensitive endpoints within 30s on u1.slingexe.com. Paths: /storage/logs/laravel.log, /.env, /.env.backup, /.env.example, /.env.bak, /.env.dev, /env, /.env.production, /.env.local. UA: crusader-worker/1.0.
show less
Web App Attack
Bad Web Bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 12:33:24
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.44.92 (92.44.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.44.92 (92.44.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:33:15.504475 2026] [security2:error] [pid 19333:tid 19333] [client 136.108.44.92:42926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigislandhawaiirealty.com"] [uri "/.env.prod"] [unique_id "apAui-EOLpjVVUbYvuedLwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 12:09:50
(7 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.cardioacademy.gr; logs=/var/log/httpd/domains/cardioaca ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.cardioacademy.gr; logs=/var/log/httpd/domains/cardioacademy.gr.log; samples=/.env | /wp-config.php.bak | /.env.old
show less
Hacking
Web App Attack