🇩🇪
MusicLibrary
2026-09-06 00:17:30
(10 minutes ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-06 00:02:40
(25 minutes ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-05 23:53:38
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:53:31.196715 2026] [security2:error] [pid 19403:tid 19403] [client 136.67.144.221:60222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.l39capital.com"] [uri "/.env.backup"] [unique_id "apyre3dpft0kg-YKiC0jJgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ISPLtd
2026-09-05 23:52:28
(35 minutes ago)
Sep 5 20:52:27 136.67.144.221 TCP SPT=34624 DPT=80 SYN
Sep 5 20:52:27 136.67.144.221 TCP SPT=34632 ...
show more
Sep 5 20:52:27 136.67.144.221 TCP SPT=34624 DPT=80 SYN
Sep 5 20:52:27 136.67.144.221 TCP SPT=34632 DPT=80 SYN
Sep 5 20:52:27 136.67.144.221 TCP SPT=34620 DPT=80 SYN
S
...
show less
DDoS Attack
🇩🇪
raph
2026-09-05 23:36:52
(51 minutes ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-05 22:34:42
(1 hour ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:22:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:22:12.462385 2026] [security2:error] [pid 13182:tid 13182] [client 136.67.144.221:43610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyclelytz.com.indie100.com"] [uri "/.env.dev"] [unique_id "apyWFCDog1D10TUEqZhWeAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-05 22:03:02
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-05 21:36:25
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:36:17.570627 2026] [security2:error] [pid 3505777:tid 3505899] [client 136.67.144.221:56334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siestakeybch.com"] [uri "/.env.local"] [unique_id "apyLUf3Jx5DkjDVB6KJnBQAAAcY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 21:03:25
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 21:02:25
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:46:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:46:11.273287 2026] [security2:error] [pid 17822:tid 17822] [client 136.67.144.221:33754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "architx.com"] [uri "/wp-config.php.swp"] [unique_id "apx_k6J92nq-jhwST0iTVgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-05 20:45:18
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 20:29:53
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.144.221 (221.144.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:29:45.566663 2026] [security2:error] [pid 7726:tid 7726] [client 136.67.144.221:47816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livresanciens.fritsknuf.com"] [uri "/wp-config.php~"] [unique_id "apx7ucGxzVe9CtSwbdxLbgAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
LoneRider
2026-09-05 07:23:47
(17 hours ago)
[05/Sep/2026:09:23:47.326583 +0200] apvDg_8s2YpLA6SBUzvrXwAAAAA 136.67.144.221 54042 127.0.0.1 7081
...
show more
[05/Sep/2026:09:23:47.326583 +0200] apvDg_8s2YpLA6SBUzvrXwAAAAA 136.67.144.221 54042 127.0.0.1 7081
[05/Sep/2026:09:23:47.329999 +0200] apvDg3jZeWoDxi7L6JXksAAAAAM 136.67.144.221 54044 127.0.0.1 7081
[05/Sep/2026:09:23:47.336186 +0200] apvDgzq94xtrXLqyXdOdegAAAAU 136.67.144.221 54054 127.0.0.1 7081
...
show less
Hacking