🇳🇱
homeshowdomain.nl
2026-08-28 22:01:23
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-08-28 19:26:08
(2 days ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
🇬🇧
openstrike.co.uk
2026-08-28 05:14:03
(2 days ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.local HTTP/1.1
Web App Attack
Hacking
🇬🇧
knock
2026-08-27 22:10:17
(3 days ago)
Knock-Knock honeypot brute-force: proto8 (19 total hits)
Brute-Force
🇳🇱
homeshowdomain.nl
2026-08-27 22:03:31
(3 days ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
🇧🇷
Peregrine
2026-08-27 21:21:12
(3 days ago)
Fail2Ban Jail s2: tomcat-404 | Evidence: - 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /_ign ...
show more
Fail2Ban Jail s2: tomcat-404 | Evidence: - 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /_ignition/health-check HTTP/1.1" 404 414
- 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /env HTTP/1.1" 404 414
- 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /actuator/configprops HTTP/1.1" 404 414
- 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /actuator/env HTTP/1.1" 404 414
- 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 414
- 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /crusader-404-probe HTTP/1.1" 404 414
- 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /wp-config.php.swp HTTP/1.1" 404 414
- 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /storage/logs/laravel.log HTTP/1.1" 404 414
- 136.64.73.204 - - [27/Aug/2026:18:21:10 -0300] "GET /wp-config.php~ HTTP/1.1" 404 414
show less
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-08-27 21:20:22
(3 days ago)
.env scanning [BY]
Web App Attack
🇩🇪
Enno
2026-08-27 21:02:56
(3 days ago)
X09::Fail2Ban: automated bot scanning / credential probing detected.
Web App Attack
Bad Web Bot
🇺🇸
mnsf
2026-08-27 20:05:13
(3 days ago)
Abuse Detected (10)
Brute-Force
Web App Attack
🇺🇸
ipblock.com
2026-08-27 19:32:00
(3 days ago)
IPBlock protected site ID [1365-l].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 19:16:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.73.204 (204.73.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.73.204 (204.73.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:16:49.004826 2026] [security2:error] [pid 18375:tid 18375] [client 136.64.73.204:51314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelsabbey.com"] [uri "/.env.save"] [unique_id "apCNIT7UbGwYLhg_T2j6CwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
IVski.com
2026-08-27 18:24:37
(3 days ago)
IVski WAF | Sensitive file probe - looking for exposed .env and .git config
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-27 18:03:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.73.204 (204.73.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.73.204 (204.73.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:03:41.350942 2026] [security2:error] [pid 4715:tid 4715] [client 136.64.73.204:46608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mylert.org"] [uri "/.env"] [unique_id "apB7_ZUhstiEDfpHBs-PcAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-08-27 17:43:39
(3 days ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:16:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.73.204 (204.73.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.73.204 (204.73.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:16:18.112974 2026] [security2:error] [pid 16197:tid 16197] [client 136.64.73.204:48352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.trade.dodojuice.com"] [uri "/.env.old"] [unique_id "apBw4jVu3UPhwVzm4ZNJfQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack