🇩🇪
kkw
2026-09-04 14:59:55
(1 day ago)
[REDACTED] 136.66.54.154 - - [04/Sep/2026:16:59:55 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4512 ...
show more
[REDACTED] 136.66.54.154 - - [04/Sep/2026:16:59:55 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4512 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 14:55:38
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇷🇴
clauss
2026-09-04 14:18:30
(1 day ago)
136.66.54.154 - - [04/Sep/2026:17:18:29 +0300] "GET /actuator/configprops HTTP/1.1" 404 5752 "-" "cr ...
show more
136.66.54.154 - - [04/Sep/2026:17:18:29 +0300] "GET /actuator/configprops HTTP/1.1" 404 5752 "-" "crusader-worker/1.0"
136.66.54.154 - - [04/Sep/2026:17:18:29 +0300] "GET /.env.prod HTTP/1.1" 404 5752 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:13:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.66.54.154 (154.54.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.54.154 (154.54.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:13:32.743862 2026] [security2:error] [pid 8132:tid 8132] [client 136.66.54.154:34994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.susanleeward.com"] [uri "/.env.example"] [unique_id "aprSDAf4BqwykndFWN39VwAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
arsonist
2026-09-04 14:11:16
(1 day ago)
[fail2ban]
2026-09-04T14:11:16.068583+00:00 arson caddy[1890453]: {"level":"info","ts":1788531076.05 ...
show more
[fail2ban]
2026-09-04T14:11:16.068583+00:00 arson caddy[1890453]: {"level":"info","ts":1788531076.0598118,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"136.66.54.154","remote_port":"38992","client_ip":"136.66.54.154","proto":"HTTP/1.1","method":"GET","host":"wd.arson.gg","uri":"/.env","headers":{"User-Agent":["crusader-worker/1.0"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"wd.arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000067206,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
🇩🇪
todix
2026-09-04 14:09:55
(1 day ago)
Web App Attack Exploid from 136.66.54.154
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:49:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.66.54.154 (154.54.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.54.154 (154.54.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:49:24.358191 2026] [security2:error] [pid 28856:tid 28856] [client 136.66.54.154:53596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agreyhawkcampaign.net"] [uri "/.env.local"] [unique_id "aprMZEgCrlbm8bUMkt5d-AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:17:57
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 12:32:37
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.66.54.154 (154.54.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.54.154 (154.54.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:32:33.924462 2026] [security2:error] [pid 4164:tid 4164] [client 136.66.54.154:41500] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gkerby.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gkerby.com"] [uri "/storage/logs/laravel.log"] [unique_id "apq6YRMEakiD5jexHvZabAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 12:20:17
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 12:05:28
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 12:02:09
(1 day ago)
[04/Sep/2026:15:02:09 +0300] -- 136.66.54.154 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[04/Sep/2026:15:02:09 +0300] -- 136.66.54.154 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 11:20:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:16:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.66.54.154 (154.54.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.54.154 (154.54.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:03.361483 2026] [security2:error] [pid 475:tid 475] [client 136.66.54.154:38256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.golflavahotsprings.com"] [uri "/.env.prod"] [unique_id "apqoc3CZpgtKiv1NeXqf9AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 10:57:35
(1 day ago)
Multiple WAF Violations
Web App Attack