๐ง๐ช
sid3windr
2026-08-28 09:16:57
(2 minutes ago)
GET /.bash_history (Tarpitted for 4m20s, wasted 15.35kB)
Web App Attack
๐ฉ๐ช
loveprod
2026-08-27 22:21:25
(10 hours ago)
136.116.251.74 - - [28/Aug/2026:01:21:24 +0300] "GET /.env.old HTTP/2.0" 403 352 "-" "crusader-worke ...
show more
136.116.251.74 - - [28/Aug/2026:01:21:24 +0300] "GET /.env.old HTTP/2.0" 403 352 "-" "crusader-worker/1.0"
136.116.251.74 - - [28/Aug/2026:01:21:24 +0300] "GET /.env.dev HTTP/2.0" 403 352 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:02:29
(11 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
Anonymous
2026-08-27 21:00:09
(12 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐ง๐พ
lns.bz
2026-08-27 20:52:16
(12 hours ago)
.env scanning [BY]
Web App Attack
๐ฉ๐ช
on-com
2026-08-27 19:46:01
(13 hours ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:27:28
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.251.74 (74.251.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.251.74 (74.251.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:27:20.646716 2026] [security2:error] [pid 30264:tid 30301] [client 136.116.251.74:48192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.guitarprimer.iancaird.com"] [uri "/wp-config.php.bak"] [unique_id "apCBiChiGJYuIb3qVApqXQAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 18:20:03
(14 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 18:05:17
(15 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-27 17:25:03
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 15:52:10
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.251.74 (74.251.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.251.74 (74.251.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:52:06.008376 2026] [security2:error] [pid 10198:tid 10198] [client 136.116.251.74:52794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegrabbagshow.com"] [uri "/.env.backup"] [unique_id "apBdJlUCOC1Aw04npkNc1wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 15:06:06
(18 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:44:48
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.251.74 (74.251.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.251.74 (74.251.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:44:39.771349 2026] [security2:error] [pid 31289:tid 31289] [client 136.116.251.74:35832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swwpccpa.com"] [uri "/.env.backup"] [unique_id "apBNVy_hfeHHfDQT7bNBZgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 13:10:01
(20 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:55:29
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.251.74 (74.251.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.251.74 (74.251.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:55:24.926626 2026] [security2:error] [pid 16948:tid 16948] [client 136.116.251.74:38010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "camairhvac.com"] [uri "/.env.old"] [unique_id "apAzvPrKmz4GjfH8No8okAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack