๐ซ๐ท
ACE-INFORMATIQUE.NC
2026-09-01 19:00:08
(1 hour ago)
Web App Attack blocked by Fail2ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:57:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.104.59 (59.104.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.104.59 (59.104.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:57:54.318227 2026] [security2:error] [pid 4286:tid 4286] [client 136.67.104.59:32944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alsetsystems.com"] [uri "/wp-config.php.swp"] [unique_id "apavskg8HaULwhpCWnc2EwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-09-01 10:52:51
(9 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
CBJ
2026-09-01 10:49:13
(9 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
RH5
2026-09-01 10:20:47
(10 hours ago)
Restricted URL probing (/wp-config) (UTC 2026-09-01 10:20)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:15:59
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.104.59 (59.104.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.104.59 (59.104.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:15:54.504354 2026] [security2:error] [pid 24934:tid 24934] [client 136.67.104.59:34780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acctusa.net"] [uri "/.env.save"] [unique_id "apal2nWIiTnsNSMBeA-ABgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 09:27:05
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐จ๐ฑ
Denis Chavez
2026-09-01 09:22:53
(11 hours ago)
Fail2Ban detected malicious activity on Nginx
Brute-Force
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:30:45
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.104.59 (59.104.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.104.59 (59.104.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:30:37.985289 2026] [security2:error] [pid 7403:tid 7403] [client 136.67.104.59:48406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mailx.semisysteme.com"] [uri "/.env.example"] [unique_id "apaNLRcL2virqNxagFMGHwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:48:23
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.104.59 (59.104.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.104.59 (59.104.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:48:16.524801 2026] [security2:error] [pid 2972:tid 2972] [client 136.67.104.59:38190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gallodestinationservices.com"] [uri "/wp-config.php.bak"] [unique_id "apaDQGzTGtZe-gF3_rFzxgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 07:43:21
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
Baking333
2026-09-01 05:42:07
(14 hours ago)
[redacted] 136.67.104.59 - - [01/Sep/2026:06:42:06 +0100] "GET /.[redacted] HTTP/1.1" 302 6753 0/574 ...
show more
[redacted] 136.67.104.59 - - [01/Sep/2026:06:42:06 +0100] "GET /.[redacted] HTTP/1.1" 302 6753 0/57471 "-" "crusader-worker/1.0" [redacted] 136.67.104.59 - - [01/Sep/2026:06:42:06 +0100] "GET /.[redacted] HTTP/1.1" 302 6753 0/51894 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-01 05:07:23
(15 hours ago)
[TueSep0107:07:21.2835222026][security2:error][pid3698297:tid3698421][client136.67.104.59:0]ModSecur ...
show more
[TueSep0107:07:21.2835222026][security2:error][pid3698297:tid3698421][client136.67.104.59:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.grigorov.ch\"][uri\"/storage/logs/laravel.log\"][unique_id\"apZdiTK3_cVTUz0iHR492wAAAQ0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
Gabriel Camargo
2026-09-01 04:42:18
(15 hours ago)
136.67.104.59 - - [31/Aug/2026:23:42:18 -0500] "GET /.env.local HTTP/1.1" 301 178 "-" "crusader-work ...
show more
136.67.104.59 - - [31/Aug/2026:23:42:18 -0500] "GET /.env.local HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
136.67.104.59 - - [31/Aug/2026:23:42:18 -0500] "GET /.env.bak HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
136.67.104.59 - - [31/Aug/2026:23:42:18 -0500] "GET /storage/logs/laravel.log HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
Anonymous
2026-09-01 04:25:43
(15 hours ago)
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /crusader-404-probe HTTP/1.1" 403 12583 "-" "cru ...
show more
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /crusader-404-probe HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /wp-config.php~ HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /_ignition/health-check HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /env HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /.env.old HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /.env.backup HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
136.67.104.59 - - [01/Sep/2026:06:25:39 +0200] "GET /.env HTTP/1.1" 403 12583 "-" "
...
show less
Bad Web Bot
Web App Attack