🇳🇱
homeshowdomain.nl
2026-08-29 22:01:07
(1 hour ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
🇲🇽
octageeks.com
2026-08-29 04:27:41
(19 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇮🇪
AutosOnShow
2026-08-29 01:58:05
(21 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-08-29 01:57:34.171 |
Web App Attack
🇩🇪
FeG Deutschland
2026-08-29 01:30:43
(22 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇫🇷
✨
2026-08-29 01:16:07
(22 hours ago)
Domain : ability4.co.uk
Rule : env
2026-08-29 01:15:12 ***hidden-privacy*** GET /.env.example - 443 ...
show more
Domain : ability4.co.uk
Rule : env
2026-08-29 01:15:12 ***hidden-privacy*** GET /.env.example - 443 - 136.65.156.153 HTTP/1.1 crusader-worker/1.0 - ability4.co.uk 301 0 0 436 98 104 - -
show less
Hacking
SQL Injection
🇺🇸
mnsf
2026-08-29 00:09:01
(23 hours ago)
Abuse Detected (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:50:00
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.156.153 (153.156.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.156.153 (153.156.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:49:56.436962 2026] [security2:error] [pid 3945:tid 3945] [client 136.65.156.153:36792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crearcuestionarios.com.creartest.com"] [uri "/wp-config.php.bak"] [unique_id "apIepPL5nWaeP9uftCyweAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 22:00:45
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-28 21:58:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.65.156.153 (153.156.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.156.153 (153.156.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:58:12.938087 2026] [security2:error] [pid 28459:tid 28459] [client 136.65.156.153:32802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elessenlabz.com.lucid-events.com"] [uri "/.env.bak"] [unique_id "apIEdKxjJgoEHRMualnVQwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:39:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.65.156.153 (153.156.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.156.153 (153.156.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:39:44.129013 2026] [security2:error] [pid 20371:tid 20371] [client 136.65.156.153:47506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.orchids-themovie.hartflicker.com"] [uri "/wp-config.php.bak"] [unique_id "apIAIK8DwNx6euGgMb79GwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 20:37:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.65.156.153 (153.156.65.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.156.153 (153.156.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:37:33.158401 2026] [security2:error] [pid 15565:tid 15692] [client 136.65.156.153:48714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dwcwelding.com.eliteproductions.tv"] [uri "/wp-config.php.swp"] [unique_id "apHxjWL4QxVkmAxTPfSTCQAAAgE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 20:05:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-28 19:45:03
(1 day ago)
136.65.156.153 - - [28/Aug/2026:19:45:02 +0000] "GET /.env HTTP/1.1" 302 4912 "-" "crusader-worker/1 ...
show more
136.65.156.153 - - [28/Aug/2026:19:45:02 +0000] "GET /.env HTTP/1.1" 302 4912 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
MaxMeier
2026-08-28 18:55:05
(1 day ago)
136.65.156.153 - - [28/Aug/2026:20:54:03 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 444 0 "-" " ...
show more
136.65.156.153 - - [28/Aug/2026:20:54:03 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
136.65.156.153 - - [28/Aug/2026:20:54:03 +0200] "GET /.env.local HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
136.65.156.153 - - [28/Aug/2026:20:54:03 +0200] "GET /.env.example HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
136.65.156.153 - - [28/Aug/2026:20:54:03 +0200] "GET /actuator/configprops HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
136.65.156.153 - - [28/Aug/2026:20:54:03 +0200] "GET /wp-config.php.swp HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
136.65.156.153 - - [28/Aug/2026:20:54:04 +0200] "GET /.env.save HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
136.65.156.153 - - [28/Aug/2026:20:54:04 +0200] "GET /.env.old HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
136.65.156.153 - - [28/Aug/2026:20:54:04 +0200] "GET /.env HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-08-28 18:36:32
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack