🇳🇱
ConsulHosting
2026-09-08 07:18:06
(19 hours ago)
Automatically blocked due to distributed attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-07 21:59:33
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇬🇧
Marten Mark
2026-09-07 21:39:01
(1 day ago)
136.67.138.204 - - [07/Sep/2026:21:39:00 +0000] "GET /.env HTTP/1.1" 301 166 "-" "crusader-worker/1. ...
show more
136.67.138.204 - - [07/Sep/2026:21:39:00 +0000] "GET /.env HTTP/1.1" 301 166 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
aks4226
2026-09-07 05:34:12
(1 day ago)
Bot search, attacking common web applications.
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-06 08:15:25
(2 days ago)
[Sun Sep 06 18:15:24.030840 2026] [security2:error] [pid 903512] [client 136.67.138.204:52414] [clie ...
show more
[Sun Sep 06 18:15:24.030840 2026] [security2:error] [pid 903512] [client 136.67.138.204:52414] [client 136.67.138.204] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/db.sql"] [unique_id "ap0hHC0lLTch4O-hLgFeWQAAAFw"], referer: https://ec2-13-54-104-103.ap-southeast-2.compute.amazonaws.com/db.sql
...
show less
Web App Attack
🇲🇾
Rizzy
2026-09-06 03:38:26
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇭🇺
DumaNet
2026-09-06 03:24:00
(2 days ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 06. 05:06:11
Source IP: 136.67 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 06. 05:06:11
Source IP: 136.67.138.204
Portion of the log(s):
136.67.138.204 - [06/Sep/2026:05:06:11 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.67.138.204 - [06/Sep/2026:05:06:11 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.67.138.204 - [06/Sep/2026:05:06:11 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.67.138.204 - [06/Sep/2026:05:06:11 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.67.138.204 - [06/Sep/2026:05:06:11 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.67.138.204 - [06/Sep/2026:05:06:11 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.67.138.204 - [06/Sep/2026:05:06:11 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.67.138.204 - [06/Sep/2026:05:06:11 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-06 02:08:00
(3 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 01:38:53
(3 days ago)
Multiple WAF Violations
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-06 01:07:02
(3 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:51:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.67.138.204 (204.138.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.138.204 (204.138.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:51:43.830525 2026] [security2:error] [pid 32130:tid 32130] [client 136.67.138.204:55354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esprit.enselme.com"] [uri "/.env.local"] [unique_id "apy5Hw6WgcK9uTS95O5F2QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-06 00:38:18
(3 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:36:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.67.138.204 (204.138.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.138.204 (204.138.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:36:10.446273 2026] [security2:error] [pid 13103:tid 13103] [client 136.67.138.204:53980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "holidaycalendarcards.com"] [uri "/.env.bak"] [unique_id "apy1euN-LzeYFGcwpnd2bQAAAHw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 00:05:55
(3 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇩🇪
Philister11
2026-09-06 00:00:36
(3 days ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking