๐ฌ๐ง
consul.to
2026-08-28 13:05:56
(27 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:44:35
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.115.188.127 (127.188.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.188.127 (127.188.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:44:29.106170 2026] [security2:error] [pid 11880:tid 11900] [client 136.115.188.127:51474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deathconfusion.mylordsday.com"] [uri "/.env.local"] [unique_id "apGCrXoZYSCptdot7qh4JAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-28 12:14:47
(1 hour ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
Anonymous
2026-08-28 12:12:05
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.bak HTTP/1.1, GET /.env.dev HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.bak HTTP/1.1, GET /.env.dev HTTP/1.1, GET /env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.production HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.save HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
pinguin
2026-08-28 11:46:08
(1 hour ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 11:26:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.188.127 (127.188.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.188.127 (127.188.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:26:53.866374 2026] [security2:error] [pid 11937:tid 11937] [client 136.115.188.127:50868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grandriverhomes.com"] [uri "/.env.local"] [unique_id "apFwfUrbjVO0g_-AUJp4NgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-08-28 10:19:39
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 21:25:02
(16 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
larse99
2026-08-27 20:58:23
(16 hours ago)
Detected Scanning / Hacking activity
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 18:40:40
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.188.127 (127.188.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.188.127 (127.188.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:40:33.399900 2026] [security2:error] [pid 23863:tid 23863] [client 136.115.188.127:47048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.female.bodybuildbid.com"] [uri "/.env"] [unique_id "apCEocKcbR76DNGTzLepeAAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 17:44:32
(19 hours ago)
Scan for .env Files at 2026-08-27T17:44:32+00:00
Web App Attack
๐จ๐ฆ
smithoo4
2026-08-27 17:36:50
(19 hours ago)
136.115.188.127 - - [27/Aug/2026:13:36:49 -0400] "GET /crusader-404-probe HTTP/1.1" 444 0 "-" "crusa ...
show more
136.115.188.127 - - [27/Aug/2026:13:36:49 -0400] "GET /crusader-404-probe HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
136.115.188.127 - - [27/Aug/2026:13:36:49 -0400] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Port Scan
Bad Web Bot
๐ฉ๐ช
gadix
2026-08-27 17:35:47
(19 hours ago)
[27/Aug/2026:19:35:47.240688 +0200] apB1c9-65245T8t75U2DAgAAAAI 136.115.188.127 43516 127.0.0.1 7081 ...
show more
[27/Aug/2026:19:35:47.240688 +0200] apB1c9-65245T8t75U2DAgAAAAI 136.115.188.127 43516 127.0.0.1 7081
[27/Aug/2026:19:35:47.247434 +0200] apB1c4Uhnuqmvzj_fJSNfQAAAAM 136.115.188.127 43528 127.0.0.1 7081
[27/Aug/2026:19:35:47.250813 +0200] apB1c4Uxug5n7bY54aTogAAAAA4 136.115.188.127 43530 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-08-27 17:35:15
(19 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ซ๐ท
Baking333
2026-08-27 17:19:22
(20 hours ago)
[redacted] 136.115.188.127 - - [27/Aug/2026:18:19:20 +0100] "GET /.[redacted] HTTP/1.1" 302 6753 0/1 ...
show more
[redacted] 136.115.188.127 - - [27/Aug/2026:18:19:20 +0100] "GET /.[redacted] HTTP/1.1" 302 6753 0/123305 "-" "crusader-worker/1.0" [redacted] 136.115.188.127 - - [27/Aug/2026:18:19:20 +0100] "GET /.[redacted] HTTP/1.1" 302 6753 0/111135 "-" "crusader-worker/1.0" [redacted] 136.115.188.127 - - [27/Aug/2026:18:19:20 +0100] "GET /.[redacted] HTTP/1.1" 302 6753 0/113456 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack