Anonymous
2026-09-01 23:08:16
(18 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-01 12:44:10
(1 day ago)
[server.techsupportltd.gr] httpd-config-scan: sites=www.chro.gr; logs=/var/log/httpd/domains/chro.gr ...
show more
[server.techsupportltd.gr] httpd-config-scan: sites=www.chro.gr; logs=/var/log/httpd/domains/chro.gr.log; samples=/.env.save | /.env.production | /.env.dev
show less
Hacking
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-01 11:59:42
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 11:10:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:10:11.654284 2026] [security2:error] [pid 20949:tid 20949] [client 136.110.79.107:46646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.crowmoonmarketing.com"] [uri "/.env.example"] [unique_id "apaykwn3uyMh61_RWTzXWQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 11:02:31
(1 day ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-09-01 10:55:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:55:04.890365 2026] [security2:error] [pid 12319:tid 12319] [client 136.110.79.107:46228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petermunka.com"] [uri "/.env.bak"] [unique_id "apavCI-cxakrBWzL_uvZEgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-09-01 07:03:00
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.110.79.107 (JP/Japan/107.79.110.136. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.110.79.107 (JP/Japan/107.79.110.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.110.79.107 - - [01/Sep/2026:09:02:58 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=freddiegroup.com
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-01 06:05:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:05:00.304507 2026] [security2:error] [pid 4390:tid 4390] [client 136.110.79.107:47640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.scermak.com"] [uri "/.env.local"] [unique_id "apZrDCiCJ4sdjb4NKOmkqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 05:21:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:20:55.052446 2026] [security2:error] [pid 17341:tid 17341] [client 136.110.79.107:53318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ericeschenbach.com"] [uri "/.env.production"] [unique_id "apZgtyA9MYg5z80lg3EX4QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-01 04:51:27
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-09-01 04:51 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:30:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:30:39.579349 2026] [security2:error] [pid 31215:tid 31215] [client 136.110.79.107:53996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boederinteriordesign.com"] [uri "/.env.backup"] [unique_id "apZU77kc39NzwzlcGibbQQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-01 04:09:49
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 03:48:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:48:03.530584 2026] [security2:error] [pid 30921:tid 30921] [client 136.110.79.107:59396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guavaroad.com"] [uri "/wp-config.php.swp"] [unique_id "apZK83ejUBgasDKS1dZkAgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 02:43:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.79.107 (107.79.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:43:40.995576 2026] [security2:error] [pid 28575:tid 28578] [client 136.110.79.107:51916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jonathanarlook.com"] [uri "/wp-config.php.swp"] [unique_id "apY73EqCN7_eadEqktdPlQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
boxed-it
2026-09-01 02:39:13
(1 day ago)
GET /_ignition/health-check (Tarpitted for 4m22s, wasted 15.47kB)
Web App Attack