🇹🇼
tyetriiix
2026-09-06 06:16:36
(1 hour ago)
Wazuh Alert Evidence: 136.70.69.231 - - [06/Sep/2026:06:16:34 +0000] "GET /.env.local HTTP/1.1" 403 ...
show more
Wazuh Alert Evidence: 136.70.69.231 - - [06/Sep/2026:06:16:34 +0000] "GET /.env.local HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" Origin: "-" CORS_Header: "-" Sent_allow_origin: "-"
show less
Web App Attack
Anonymous
2026-09-06 04:05:09
(3 hours ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:48:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.69.231 (231.69.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.69.231 (231.69.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:48:41.578798 2026] [security2:error] [pid 25806:tid 25806] [client 136.70.69.231:47004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lincolnsoftwareinc.com"] [uri "/.env.prod"] [unique_id "apzimUXmgsmfwHKjmXsSeQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 03:40:23
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-06 03:37:03
(4 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.prod HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.prod HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.example HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:12
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.69.231 (231.69.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.69.231 (231.69.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:04.246801 2026] [security2:error] [pid 27528:tid 27528] [client 136.70.69.231:35560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.terryhildebrandprints.com"] [uri "/wp-config.php~"] [unique_id "apzWgOGcTji-Eo6fXr7GsAAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-06 02:27:29
(5 hours ago)
.env scanning [BY]
Web App Attack
🇺🇸
mnsf
2026-09-06 02:05:26
(5 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇩🇪
maxpower
2026-09-06 01:45:47
(5 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.70.69.231 (US/United States/231.69.7 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.70.69.231 (US/United States/231.69.70.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.70.69.231 - - [06/Sep/2026:03:45:43 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11932 "-" "crusader-worker/1.0" "-" host=ftp.poderedellatorre.it
show less
Port Scan
🇨🇭
zynex
2026-09-06 01:41:36
(5 hours ago)
URL Probing: /wp-config.php~
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 01:36:52
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
debestelapp
2026-09-06 01:15:10
(6 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:09:53
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.69.231 (231.69.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.69.231 (231.69.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:47.987307 2026] [security2:error] [pid 28946:tid 28956] [client 136.70.69.231:33580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.martinbenes.com"] [uri "/.env"] [unique_id "apy9W8iKLOccEIT5yWoI7gAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 00:07:14
(7 hours ago)
Domain : pensive-burnell.88-150-137-20.plesk.page
Rule : hack
2026-09-06 00:04:45 ***hidden-privacy* ...
show more
Domain : pensive-burnell.88-150-137-20.plesk.page
Rule : hack
2026-09-06 00:04:45 ***hidden-privacy*** GET /.env.bak - 80 - 136.70.69.231 HTTP/1.1 crusader-worker/1.0 - pensive-burnell.***hidden-privacy***.plesk.page 307 0 0 345 120 77 - -
show less
Hacking
SQL Injection
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 00:03:48
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.69.231 (231.69.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.69.231 (231.69.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:03:44.136961 2026] [security2:error] [pid 3469408:tid 3469408] [client 136.70.69.231:49356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentuckyminiaturehorsebreeders.org"] [uri "/wp-config.php.swp"] [unique_id "apyt4GXKg6wHfat-pSd8ugAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack