πΊπΈ
Sonoflet
2026-09-30 19:22:00
(1 hour ago)
CrowdSec detection | scenario: http-path-traversal-probing
Web App Attack
Exploited Host
π«π·
LoneRider
2026-09-30 19:14:25
(1 hour ago)
[30/Sep/2026:21:14:24.266802 +0200] ar1fkMb4oQF1BjXmTbvZ5AAAAAg 136.118.198.107 52402 127.0.0.1 7081 ...
show more
[30/Sep/2026:21:14:24.266802 +0200] ar1fkMb4oQF1BjXmTbvZ5AAAAAg 136.118.198.107 52402 127.0.0.1 7081
[30/Sep/2026:21:14:24.267079 +0200] ar1fkDEQwT2x0P3RyRLndQAAAAQ 136.118.198.107 52374 127.0.0.1 7081
[30/Sep/2026:21:14:24.267583 +0200] ar1fkAgbZlfDhuhq3TXkuQAAAAU 136.118.198.107 52386 127.0.0.1 7081
...
show less
Hacking
π³π±
Site.eu
2026-09-30 18:27:34
(2 hours ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
TheDjRider
2026-09-30 17:43:30
(3 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-09-30T17:43:27.581860705Z. Context: http_status=404
show less
Web App Attack
π―π΅
VXG-NET
2026-09-30 16:44:10
(4 hours ago)
port=80, indicator_type=insecure-credentials
Brute-Force
π©πͺ
stinpriza
2026-09-30 16:23:43
(4 hours ago)
common Web Exploits being scanned
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:40:18
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.198.107 (107.198.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.198.107 (107.198.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:40:14.530309 2026] [security2:error] [pid 14251:tid 14251] [client 136.118.198.107:58314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nomanszone.com.nomanszone.org"] [uri "/@fs/app/.env"] [unique_id "ar0tXrqAHUhlt12Pnv48nwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-09-30 15:18:47
(5 hours ago)
Aggressive web search of vulnerable pages: /api/fs/read?allowOutsideWorkspace=true&path=/app/.env /c ...
show more
Aggressive web search of vulnerable pages: /api/fs/read?allowOutsideWorkspace=true&path=/app/.env /cache/original/%2e%2e/.env /cache/original/% ...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:18:33
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.198.107 (107.198.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.198.107 (107.198.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:18:25.720780 2026] [security2:error] [pid 31668:tid 31668] [client 136.118.198.107:45754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cyber-matrix.org"] [uri "/.env.js"] [unique_id "ar0oQQ0H3Iu2-IaEUyZQNgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-30 14:41:20
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-30 14:39:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.198.107 (107.198.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.198.107 (107.198.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:39:02.506169 2026] [security2:error] [pid 24011:tid 24011] [client 136.118.198.107:53468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "professionalpartyplanner.org"] [uri "/.env.dev"] [unique_id "ar0fBpwIR7L0W32tr00WpwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WellSpring
2026-09-30 14:35:12
(6 hours ago)
good bot honeypot on odypays.org/secrets.env β WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Anonymous
2026-09-30 14:20:02
(6 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
π©πͺ
macrob
2026-09-30 14:08:31
(6 hours ago)
2026/09/30 14:08:29 [error] 1318205#1318205: *1387437 access forbidden by rule, client: 136.118.198. ...
show more
2026/09/30 14:08:29 [error] 1318205#1318205: *1387437 access forbidden by rule, client: 136.118.198.107, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "remote.nuvello.org"
2026/09/30 14:08:29 [error] 1318205#1318205: *1387438 access forbidden by rule, client: 136.118.198.107, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "remote.nuvello.org"
2026/09/30 14:08:29 [error] 1318207#1318207: *1387443 access forbidden by rule, client: 136.118.198.107, server: fn.binixo.es, request: "GET /.//.env HTTP/2.0", host: "remote.nuvello.org"
...
show less
Web App Attack
πΊπΈ
Sonoflet
2026-09-30 14:06:40
(6 hours ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host