🇳🇱
homeshowdomain.nl
2026-09-05 22:00:24
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇫🇷
SpaceHost-Server
2026-09-04 22:15:18
(2 days ago)
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:01:16
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇳🇱
e.fierstra
2026-09-04 14:46:48
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:34:24
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 14:11:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.118.193.212 (212.193.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.193.212 (212.193.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:12.957893 2026] [security2:error] [pid 18562:tid 18562] [client 136.118.193.212:35962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.portraitartisans.com"] [uri "/.env.production"] [unique_id "aprRgEqx3Knqsn14o-fUFgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
borbolla
2026-09-04 13:51:24
(2 days ago)
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.env HTTP/1.1" "GET /.env ...
show more
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.env HTTP/1.1" "GET /.env.backup HTTP/1.1" "GET /.env.bak HTTP/1.1"
show less
Web App Attack
Bad Web Bot
🇩🇪
macrob
2026-09-04 13:38:14
(2 days ago)
2026/09/04 13:38:12 [error] 754819#754819: *555990727 access forbidden by rule, client: 136.118.193. ...
show more
2026/09/04 13:38:12 [error] 754819#754819: *555990727 access forbidden by rule, client: 136.118.193.212, server: finami.vn, request: "GET /.env.production HTTP/2.0", host: "finami-vn.com"
2026/09/04 13:38:12 [error] 754820#754820: *555990729 access forbidden by rule, client: 136.118.193.212, server: finami.vn, request: "GET /.env.example HTTP/2.0", host: "finami-vn.com"
2026/09/04 13:38:12 [error] 754819#754819: *555990731 access forbidden by rule, client: 136.118.193.212, server: finami.vn, request: "GET /.env.bak HTTP/2.0", host: "finami-vn.com"
...
show less
Web App Attack
🇩🇪
LRob
2026-09-04 13:34:56
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-09-04 13:34 UTC
show less
Hacking
Web App Attack
🇩🇪
FD-IX
2026-09-04 13:30:32
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-04 13:30:26
(2 days ago)
2026/09/04 14:30:16 [error] 380594#380594: *2799810 access forbidden by rule, client: 136.118.193.21 ...
show more
2026/09/04 14:30:16 [error] 380594#380594: *2799810 access forbidden by rule, client: 136.118.193.212, server: slcocincubator.gwynethllewelyn.net, request: "GET /.env HTTP/2.0", host: "slcocincubator.gwynethllewelyn.net"
136.118.193.212 - - [04/Sep/2026:14:30:16 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "crusader-worker/1.0"
2026/09/04 14:30:24 [error] 380594#380594: *2799810 access forbidden by rule, client: 136.118.193.212, server: slcocincubator.gwynethllewelyn.net, request: "GET //.env HTTP/2.0", host: "slcocincubator.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:50:09
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 11:09:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.118.193.212 (212.193.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.193.212 (212.193.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:09:17.407671 2026] [security2:error] [pid 365:tid 365] [client 136.118.193.212:60020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aactioninv.com"] [uri "/wp-config.php~"] [unique_id "apqm3ak7Zr-_K0dv6hv4BwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-04 10:31:32
(2 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.118.193.212 (US/United States/212.19 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.118.193.212 (US/United States/212.193.118.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.118.193.212 - - [04/Sep/2026:12:31:28 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11864 "-" "crusader-worker/1.0" "-" host=ilfaro.ovh
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 10:14:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.118.193.212 (212.193.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.193.212 (212.193.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:14:01.948017 2026] [security2:error] [pid 15689:tid 15689] [client 136.118.193.212:59220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jabbosjingles.com"] [uri "/.env.dev"] [unique_id "apqZ6d2Y3DBXeeOzXDcFBQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack