๐ณ๐ด
jad-abuse
2026-09-01 05:21:45
(9 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ignition_ ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ignition_debug, scanner_ua, actuator, env_probe, source_backup, config_backup. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:05:49
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (119.68.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (119.68.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:05:40.085686 2026] [security2:error] [pid 1798:tid 1798] [client 136.70.68.119:54410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mlundp.com"] [uri "/.env.local"] [unique_id "apZdJDDwklMimMpTtTtHJQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:40:48
(10 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.70.68.119 (US/United States/119.68.70.13 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.70.68.119 (US/United States/119.68.70.136.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.70.68.119 - - [01/Sep/2026:06:40:44 +0200] "GET /.env.dev HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
136.70.68.119 - - [01/Sep/2026:06:40:44 +0200] "GET /.env.local HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
136.70.68.119 - - [01/Sep/2026:06:40:44 +0200] "GET /.env.save HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 04:20:44
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 03:43:29
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (119.68.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (119.68.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:43:21.487135 2026] [security2:error] [pid 27893:tid 27893] [client 136.70.68.119:50320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hellosoft.magodarman.com"] [uri "/.env.save"] [unique_id "apZJ2VR8K9h_IjsNy_SK8QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-01 02:49:01
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (US/United States/119.68.70.136.b ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (US/United States/119.68.70.136.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:35:31
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (119.68.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (119.68.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:35:27.520402 2026] [security2:error] [pid 22524:tid 22524] [client 136.70.68.119:36868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.madburylibrary.org"] [uri "/.env.prod"] [unique_id "apY577osk-LLPRPRMHrVAAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Entalpi.net
2026-09-01 02:10:28
(13 hours ago)
Repeated requests against sensitive web endpoints
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 02:08:42
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 02:07:03
(13 hours ago)
Automated web scanner. Requested suspicious paths: /crusader-404-probe | /.env.example | /.env | /.e ...
show more
Automated web scanner. Requested suspicious paths: /crusader-404-probe | /.env.example | /.env | /.env.dev | /.env.production | /.env.save | /env | /storage/logs/laravel.log | /.env.old | /actuator/env | /.env.backup | /.env.bak | /actuator/configprops | /_ignition/health-check | /.env.local | /.env.prod. UTC: 2026-09-01 01:26:04.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 01:40:54
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (119.68.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.68.119 (119.68.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:40:48.617995 2026] [security2:error] [pid 30098:tid 30098] [client 136.70.68.119:45046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "halvaughan.com"] [uri "/.env.local"] [unique_id "apYtIDt5eF68AFmdEj6NUQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-09-01 01:38:45
(13 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-01 01:23:22
(13 hours ago)
15 attempts against mh-modsecurity-ban on staging2
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 00:49:32
(14 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-09-01 00:38:47
(14 hours ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack