🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:33:31
(25 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
gadix
2026-09-04 13:29:39
(29 minutes ago)
[04/Sep/2026:15:29:38.922225 +0200] aprHwtWzcWr-UviINLTFMwAAAAs 136.119.129.52 42370 127.0.0.1 7081
...
show more
[04/Sep/2026:15:29:38.922225 +0200] aprHwtWzcWr-UviINLTFMwAAAAs 136.119.129.52 42370 127.0.0.1 7081
[04/Sep/2026:15:29:38.927569 +0200] aprHwtWzcWr-UviINLTFNAAAAAg 136.119.129.52 42384 127.0.0.1 7081
[04/Sep/2026:15:29:38.932374 +0200] aprHwqjBEU99rOnFJjp6bgAAAEo 136.119.129.52 42394 127.0.0.1 7081
...
show less
Web App Attack
🇩🇪
Nevermind
2026-09-04 13:26:19
(33 minutes ago)
136.119.129.52 - - [04/Sep/2026:15:26:19 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 6233 "-" "crus ...
show more
136.119.129.52 - - [04/Sep/2026:15:26:19 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 6233 "-" "crusader-worker/1.0"
136.119.129.52 - - [04/Sep/2026:15:26:19 +0200] "GET /.env.prod HTTP/1.1" 403 6233 "-" "crusader-worker/1.0"
136.119.129.52 - - [04/Sep/2026:15:26:19 +0200] "GET /.env.local HTTP/1.1" 403 6233 "-" "crusader-worker/1.0"
136.119.129.52 - - [04/Sep/2026:15:26:19 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 6233 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:23:27
(35 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.119.129.52 (52.129.119.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.129.52 (52.129.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:23:19.896567 2026] [security2:error] [pid 10255:tid 10255] [client 136.119.129.52:56590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comfortcartel.com"] [uri "/.env.save"] [unique_id "aprGR7hHdikfsafFzey7_AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
joharikop
2026-09-04 13:18:35
(40 minutes ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:31:57
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.119.129.52 (52.129.119.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.129.52 (52.129.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:31:49.875219 2026] [security2:error] [pid 2824998:tid 2825091] [client 136.119.129.52:57984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "giere.us"] [uri "/.env.prod"] [unique_id "apq6NQ1OtXLqWHx1GpHNIQAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:07:03
(1 hour ago)
Automated web scanner. Requested suspicious paths: /.env.bak | /_ignition/health-check | /crusader-4 ...
show more
Automated web scanner. Requested suspicious paths: /.env.bak | /_ignition/health-check | /crusader-404-probe | /.env | /.env.old | /actuator/env | /.env.backup | /.env.production | /actuator/configprops | /.env.save | /storage/logs/laravel.log | /.env.local | /.env.example | /.env.dev | /env | /.env.prod. UTC: 2026-09-04 11:24:28.
show less
Web App Attack
🇺🇸
infra-monitor
2026-09-04 12:00:11
(1 hour ago)
Automated ban via infra-monitor: wordpress-probe, mgmt-path-probe, wp-sensitive-paths, +1 more
Port Scan
Web App Attack
🇫🇷
dynamix
2026-09-04 11:51:23
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:44:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.119.129.52 (52.129.119.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.129.52 (52.129.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:31.985889 2026] [security2:error] [pid 27797:tid 27797] [client 136.119.129.52:35876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.musicpolitan.com"] [uri "/.env.dev"] [unique_id "apqvH12AriTsNXVY-J8trQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 11:20:05
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-09-04 11:05:38
(2 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-04 10:49:45
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack