🇩🇪
pscriptos
2026-09-07 13:05:57
(53 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-07 12:12:07
(1 hour ago)
[07/Sep/2026:22:12:06 +1000] "GET /db.sql HTTP/1.1" 301 276 "Mozilla/5.0 (X11; Linux x86_64) AppleWe ...
show more
[07/Sep/2026:22:12:06 +1000] "GET /db.sql HTTP/1.1" 301 276 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
show less
Hacking
Web App Attack
Anonymous
2026-09-07 07:09:40
(6 hours ago)
Aggressive web scan
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:01:07
(15 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇸🇪
Per-Erik Runebert
2026-09-06 08:39:54
(1 day ago)
Excessive unauthorized requests
Hacking
🇩🇪
Ano_Nym
2026-09-06 06:27:48
(1 day ago)
CrowdSec IDS alert on VPS 217.154.115.19 (DE). Scenario: crowdsecurity/http-sensitive-files
Web App Attack
🇺🇸
ANTI SCANNER
2026-09-06 03:40:57
(1 day ago)
Scanner : /.env.local
Web Spam
🇩🇪
netclix.gr
2026-09-06 03:38:54
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 136.108.45.162 (US/United States/162.45 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.108.45.162 (US/United States/162.45.108.136.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 03:38:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.108.45.162 (162.45.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.45.162 (162.45.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:38:38.575186 2026] [security2:error] [pid 305389:tid 305438] [client 136.108.45.162:54212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwainet.com"] [uri "/wp-config.php.bak"] [unique_id "apzgPudZ4xRVqzYhVJzEMQAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:32:55
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.108.45.162 (US/United States/162.45.108. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.108.45.162 (US/United States/162.45.108.136.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.108.45.162 - - [06/Sep/2026:05:32:51 +0200] "GET /.env.backup HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
136.108.45.162 - - [06/Sep/2026:05:32:51 +0200] "GET /.env HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
136.108.45.162 - - [06/Sep/2026:05:32:51 +0200] "GET /.env.old HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 02:59:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.108.45.162 (162.45.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.45.162 (162.45.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:22.975139 2026] [security2:error] [pid 28990:tid 28999] [client 136.108.45.162:53212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dba.center"] [uri "/wp-config.php.swp"] [unique_id "apzXConbmbWWpEL5qYYUeQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Catalin Negru
2026-09-06 02:59:12
(1 day ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
conrad10781
2026-09-06 02:54:19
(1 day ago)
nginx-dot-env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:30:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.108.45.162 (162.45.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.45.162 (162.45.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:30:12.035199 2026] [security2:error] [pid 12106:tid 12106] [client 136.108.45.162:51758] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||midnightval.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "midnightval.com"] [uri "/data.sql"] [unique_id "apzQNI26BViJFfxavSyfmwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:36:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.108.45.162 (162.45.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.45.162 (162.45.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:36:00.773668 2026] [security2:error] [pid 12152:tid 12152] [client 136.108.45.162:45672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotjive.com"] [uri "/.env.example"] [unique_id "apy1cPqbgjWO7oxUjdNWDQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack