๐ฌ๐ง
Aetherweb Ark
2026-08-28 19:03:31
(14 minutes ago)
(mod_security) mod_security (id:949110) triggered by 136.70.92.192 (US/United States/192.92.70.136.b ...
show more
(mod_security) mod_security (id:949110) triggered by 136.70.92.192 (US/United States/192.92.70.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-28 18:56:44
(20 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:46:01
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.70.92.192 (192.92.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.92.192 (192.92.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:45:55.891253 2026] [security2:error] [pid 9838:tid 9838] [client 136.70.92.192:34898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guller.net"] [uri "/wp-config.php~"] [unique_id "apHXY6pBl2YJo72mEfKbIQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 18:45:47
(31 minutes ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 18:39:27
(38 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 18:35:56
(41 minutes ago)
[28/Aug/2026:21:35:55 +0300] -- 136.70.92.192 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[28/Aug/2026:21:35:55 +0300] -- 136.70.92.192 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /storage/logs/laravel.log HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 17:48:57
(1 hour ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.70.92.192 (US/United States/192.92.70.13 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.70.92.192 (US/United States/192.92.70.136.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.70.92.192 - - [28/Aug/2026:19:48:52 +0200] "GET /.env.local HTTP/1.1" 406 6626
136.70.92.192 - - [28/Aug/2026:19:48:52 +0200] "GET /.env.example HTTP/1.1" 406 6626
136.70.92.192 - - [28/Aug/2026:19:48:52 +0200] "GET /.env.old HTTP/1.1" 406 6626
show less
Port Scan
๐ณ๐ฑ
melroy89
2026-08-28 17:31:23
(1 hour ago)
136.70.92.192 - - [28/Aug/2026:19:30:22 +0200] "GET /.env.production HTTP/1.1" 404 0 "-" "crusader- ...
show more
136.70.92.192 - - [28/Aug/2026:19:30:22 +0200] "GET /.env.production HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.002
136.70.92.192 - - [28/Aug/2026:19:30:22 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.002
136.70.92.192 - - [28/Aug/2026:19:30:22 +0200] "GET /.env HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.001
136.70.92.192 - - [28/Aug/2026:19:30:22 +0200] "GET /.env.bak HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.001
136.70.92.192 - - [28/Aug/2026:19:30:22 +0200] "GET /.env.backup HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.000
136.70.92.192 - - [28/Aug/2026:19:30:22 +0200] "GET /.env.example HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.000
136.70.92.192 - - [28/Aug/2026:19:30:22 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.001
136.70
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:42:40
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.92.192 (192.92.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.92.192 (192.92.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:42:33.569503 2026] [security2:error] [pid 30985:tid 30993] [client 136.70.92.192:54996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.henrisphoto.robertdanielsllc.com"] [uri "/.env.backup"] [unique_id "apG6ebPO-s49xaS9dpxG6QAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-08-28 16:41:53
(2 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 2. First blocked: 2026-08-28.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:15:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.92.192 (192.92.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.92.192 (192.92.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:15:34.770271 2026] [security2:error] [pid 4905:tid 4905] [client 136.70.92.192:49610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carboncreekwood.com"] [uri "/.env.prod"] [unique_id "apG0JudHMlWAIJGGAUDvXQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 15:41:07
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-08-28 15:41 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
sernate
2026-08-28 15:29:02
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.92.192 (US/United States/192.92.70.136.b ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.92.192 (US/United States/192.92.70.136.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 14:28:31
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.92.192 (192.92.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.92.192 (192.92.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:28:27.123412 2026] [security2:error] [pid 16380:tid 16380] [client 136.70.92.192:47974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.footshufflerz.com"] [uri "/.env.prod"] [unique_id "apGbC2qxe_D9pjr7W2q-9wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-28 14:19:08
(4 hours ago)
Web vulnerability probing: /_ignition/health-check
Web App Attack