π¨π¦
Anytech
2026-09-01 12:39:17
(1 day ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
π«π·
Delta-shop
2026-09-01 11:55:41
(1 day ago)
PrestaShop Security Module: Suspicious path detected (/.env)
Web App Attack
π³π±
MyGlobalFlowers
2026-09-01 10:28:40
(1 day ago)
Multiple WAF Violations
Web App Attack
π«π·
masterguru
2026-09-01 09:43:26
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.108.75.123 (US/United States/123. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.108.75.123 (US/United States/123.75.108.136.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
Anonymous
2026-09-01 09:42:49
(1 day ago)
[server.tmg.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.bak | /.env.old | / ...
show more
[server.tmg.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.bak | /.env.old | /actuator/configprops
show less
Hacking
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-01 09:30:02
(1 day ago)
[01/Sep/2026:12:30:01 +0300] -- 136.108.75.123 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[01/Sep/2026:12:30:01 +0300] -- 136.108.75.123 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.old HTTP/1.1
show less
Bad Web Bot
Web App Attack
ππΊ
DumaNet
2026-09-01 08:10:00
(1 day ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 01. 02:55:14
Source IP: 136.10 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 01. 02:55:14
Source IP: 136.108.75.123
Portion of the log(s):
136.108.75.123 - [01/Sep/2026:02:55:14 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.108.75.123 - [01/Sep/2026:02:55:14 +0200] "GET /env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.108.75.123 - [01/Sep/2026:02:55:14 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.108.75.123 - [01/Sep/2026:02:55:14 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.108.75.123 - [01/Sep/2026:02:55:14 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.108.75.123 - [01/Sep/2026:02:55:14 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.108.75.123 - [01/Sep/2026:02:55:14 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.108.75.123 - [01/Sep/2026:02:55:14 +0200] "GET /.env.prod HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
π©πͺ
LRob
2026-09-01 06:44:32
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.example (+10 more) | 2026-09-01 06:44 UTC
show less
Hacking
Web App Attack
πΏπ¦
conure.sh
2026-09-01 05:33:44
(2 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:34:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.75.123 (123.75.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.75.123 (123.75.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:34:49.768397 2026] [security2:error] [pid 8377:tid 8377] [client 136.108.75.123:41978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.taxgroupsd.com"] [uri "/.env.local"] [unique_id "apZV6W8IuuygTDEeoYs0YAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-09-01 04:05:35
(2 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
π¨π
zynex
2026-09-01 03:54:38
(2 days ago)
URL Probing: /wp-config.php.bak
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 03:44:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.75.123 (123.75.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.75.123 (123.75.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:44:25.223196 2026] [security2:error] [pid 23070:tid 23070] [client 136.108.75.123:39492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guarinofurnituredesigns.com"] [uri "/wp-config.php.swp"] [unique_id "apZKGaqLTlKcykXujmCLuAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-09-01 03:36:38
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-01 03:35:06
(2 days ago)
PSCSERV WPSCAN 136.108.75.123
Bad Web Bot
Web App Attack