๐ฌ๐ง
consul.to
2026-09-22 16:39:40
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Starburst SysOp Team
2026-09-22 15:38:00
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-ams6-1)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:09:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.89.208 (208.89.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.89.208 (208.89.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:09:16.903193 2026] [security2:error] [pid 9847:tid 9847] [client 136.108.89.208:47124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "menafert.com"] [uri "/wp-config.php~"] [unique_id "arKaHAYeySY6pJ7rQVtbJAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 14:53:22
(2 days ago)
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.108.89.208 - - [22/Sep/2026:16:53:20 +0200] "GET /.env.old HTTP/1.1" 404 3302 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:51:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.89.208 (208.89.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.89.208 (208.89.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:51:26.556366 2026] [security2:error] [pid 5754:tid 5754] [client 136.108.89.208:48732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mcbrude.com"] [uri "/wp-config.php~"] [unique_id "arKV7tx-mpZ5r-GZhPaKLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
myintarweb
2026-09-22 14:42:15
(2 days ago)
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /wp-config.php.bak HTTP/1.1" 404 6757 "-" " ...
show more
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /wp-config.php.bak HTTP/1.1" 404 6757 "-" "crusader-worker/1.0"
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /.env.old HTTP/1.1" 404 6757 "-" "crusader-worker/1.0"
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /.env.prod HTTP/1.1" 404 6757 "-" "crusader-worker/1.0"
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /.env.local HTTP/1.1" 404 6757 "-" "crusader-worker/1.0"
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /.env HTTP/1.1" 404 6757 "-" "crusader-worker/1.0"
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /.env.production HTTP/1.1" 404 6757 "-" "crusader-worker/1.0"
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /.env.bak HTTP/1.1" 404 6757 "-" "crusader-worker/1.0"
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /wp-config.php.swp HTTP/1.1" 404 6757 "-" "crusader-worker/1.0"
136.108.89.208 - - [22/Sep/2026:15:42:13 +0100] 443 "GET /.env.example HTTP/1.1"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-09-22 14:30:00
(2 days ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 14:29:12
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-22 13:39:19
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 12:27:58
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 11:35:02
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-22 11:20:17
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-22 11:19:13
(2 days ago)
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 500 ...
show more
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 5008 "-" "crusader-worker/1.0"
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /.env.backup HTTP/1.1" 404 5008 "-" "crusader-worker/1.0"
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /.env.old HTTP/1.1" 404 5008 "-" "crusader-worker/1.0"
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /.env.save HTTP/1.1" 404 5008 "-" "crusader-worker/1.0"
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /wp-config.php~ HTTP/1.1" 404 5007 "-" "crusader-worker/1.0"
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /env HTTP/1.1" 404 5030 "-" "crusader-worker/1.0"
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /.env.production HTTP/1.1" 404 5030 "-" "crusader-worker/1.0"
[site]:443 136.108.89.208 - - [22/Sep/2026:13:19:08 +0200] "GET /.env.bak HTTP/1.1" 404 5031 "-" "crusader-worker/1.0"
[site]:443 136.108.89.208 -
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 11:12:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.89.208 (208.89.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.89.208 (208.89.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:12:46.032421 2026] [security2:error] [pid 12397:tid 12397] [client 136.108.89.208:48896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beckerbrokerage.net"] [uri "/.env.save"] [unique_id "arJirgs2ASml9hYYk91FngAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 10:54:26
(2 days ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.art25.gr; logs=/var/log/httpd/domains/art25.gr.log; samp ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.art25.gr; logs=/var/log/httpd/domains/art25.gr.log; samples=/actuator/configprops | /.env.local | /wp-config.php.bak
show less
Hacking
Web App Attack