๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:01:30
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ญ๐บ
DumaNet
2026-08-28 04:36:00
(3 days ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 17:11:30
Source IP: 136.64 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 17:11:30
Source IP: 136.64.69.78
Portion of the log(s):
136.64.69.78 - [27/Aug/2026:17:11:30 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.64.69.78 - [27/Aug/2026:17:11:30 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.64.69.78 - [27/Aug/2026:17:11:30 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.64.69.78 - [27/Aug/2026:17:11:30 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.64.69.78 - [27/Aug/2026:17:11:30 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.64.69.78 - [27/Aug/2026:17:11:30 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.64.69.78 - [27/Aug/2026:17:11:30 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.64.69.78 - [27/Aug/2026:17:11:30 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker
show less
Web App Attack
Anonymous
2026-08-27 22:10:12
(4 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
breubit
2026-08-27 22:07:54
(4 days ago)
136.64.69.78 - - [28/Aug/2026:00:07:54 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4433 "-" "crusad ...
show more
136.64.69.78 - - [28/Aug/2026:00:07:54 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4433 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:03:12
(4 days ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ธ๐ช
peterh
2026-08-27 21:37:00
(4 days ago)
136.64.69.78 - - [27/Aug/2026:22:16:55 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 435 "-" "crusade ...
show more
136.64.69.78 - - [27/Aug/2026:22:16:55 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 435 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
Phishing
Hacking
๐ฏ๐ต
Execoop
2026-08-27 20:31:58
(4 days ago)
HTTP secret_harvesting (observed): 19 HTTP
Brute-Force
๐ฆ๐บ
2000cn.com.au
2026-08-27 18:58:09
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฒ๐พ
Rizzy
2026-08-27 18:53:42
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:51:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.69.78 (78.69.64.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.69.78 (78.69.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:51:22.175809 2026] [security2:error] [pid 25311:tid 25311] [client 136.64.69.78:40598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buffaloweddingdeejay.com"] [uri "/.env"] [unique_id "apCHKsDiSt9bvWh4hDiGlgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-08-27 17:30:07
(4 days ago)
Scanning for exploits - /.env.production
Web App Attack
๐ซ๐ท
bazter.pro
2026-08-27 15:06:30
(4 days ago)
Auto-Ban [2026-08-27 18:06:30]: CRITICAL: .env attack; DC: Google LLC [Paths: 19] | Details: Exploit ...
show more
Auto-Ban [2026-08-27 18:06:30]: CRITICAL: .env attack; DC: Google LLC [Paths: 19] | Details: Exploit trap paths: /.env, /.env.production, /actuator/env, /.env.local, /.env.save | Sensitive files/paths: /.env, /.env.production, /actuator/env, /.env.local, /.env.save | 404 errors (19): /.env.save, /.env.backup, /.env.local, /env, /.env.prod, /.env.dev, /wp-config.php.swp, /wp-config.php.bak, /.env.production, /.env (and 9 more)
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 14:39:48
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.69.78 (78.69.64.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.69.78 (78.69.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:39:44.950284 2026] [security2:error] [pid 22651:tid 22651] [client 136.64.69.78:51204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fruitinthedesert.com"] [uri "/.env.old"] [unique_id "apBMMIIQeVm_xNiqpJHI2QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-27 14:26:30
(4 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 136.64.69.78 (US/United States/78.69 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 136.64.69.78 (US/United States/78.69.64.136.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
decisionconcepts
2026-08-27 14:02:16
(4 days ago)
136.64.69.78 - - [27/Aug/2026:07:02:15 -0700] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/ ...
show more
136.64.69.78 - - [27/Aug/2026:07:02:15 -0700] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/1.0"
136.64.69.78 - - [27/Aug/2026:07:02:15 -0700] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0"
show less
Brute-Force
SSH