🇩🇪
CELOS-SOC
2026-09-06 18:30:05
(7 hours ago)
Multiple Unauthorized VPN Login Attempts
Hacking
Brute-Force
🇺🇸
fbarela
2026-09-06 14:00:02
(12 hours ago)
FortiGate SSL VPN login failures.
Brute-Force
Hacking
🇧🇪
cmbplf
2026-05-12 19:00:13
(3 months ago)
161 requests with url.path *.env
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-12 18:12:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 107.148.158.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 107.148.158.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 14:12:33.074817 2026] [security2:error] [pid 17967:tid 17967] [client 107.148.158.42:40688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrejblatnik.com"] [uri "/.env"] [unique_id "agNtkZRmrVJPAvEPGSSa5wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-05-11 18:06:36
(3 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-11 17:34:26
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 107.148.158.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 107.148.158.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 13:34:22.684143 2026] [security2:error] [pid 16963:tid 16963] [client 107.148.158.42:59218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alphaplanning.com"] [uri "/.env"] [unique_id "agITHhmnIiimO-qSC7lSPAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-05-11 17:22:02
(3 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
🇺🇸
LotPhantom
2026-05-04 12:38:40
(4 months ago)
2026-05-04T12:30:58.251352+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1 ...
show more
2026-05-04T12:30:58.251352+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=107.148.158.42 DST=157.230.217.55 LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=11611 PROTO=TCP SPT=57731 DPT=2087 WINDOW=1024 RES=0x00 SYN URGP=0
2026-05-04T12:38:39.747623+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=107.148.158.42 DST=157.230.217.55 LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=4873 PROTO=TCP SPT=57731 DPT=2083 WINDOW=1024 RES=0x00 SYN URGP=0
...
show less
Port Scan
Hacking
Anonymous
2026-05-04 01:57:18
(4 months ago)
107.148.158.42 (US/United States/-), 5 distributed cpanel attacks on account [root] in the last 600 ...
show more
107.148.158.42 (US/United States/-), 5 distributed cpanel attacks on account [root] in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_DISTATTACK; Logs: [2026-05-03 19:57:11 -0600] info [whostmgrd] 173.239.236.144 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
[2026-05-03 19:57:08 -0600] info [whostmgrd] 173.239.236.144 - root "GET /cpsess1183511285/json-api/version HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
[2026-05-03 19:48:51 -0600] info [whostmgrd] 107.148.158.42 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
[2026-05-03 19:57:05 -0600] info [whostmgrd] 173.239.236.144 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
[2026-05-03 19:53:53 -0600] info [cpaneld] 107.148.158.42 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN cpaneld: root login is not permitted to cpaneld
IP Addresses Blocked:
173.239.236.144 (MY/Malaysia/-)
show less
Port Scan
🇩🇪
mattk
2026-05-04 01:40:39
(4 months ago)
port scan
Port Scan
🇩🇪
marcel-knorr.de
2026-05-04 01:26:50
(4 months ago)
[MK-VM2] Blocked by UFW
Brute-Force
Port Scan
🇺🇸
hostseries
2026-05-03 23:27:11
(4 months ago)
Trigger: LF_CPANEL
Brute-Force
Anonymous
2026-05-03 21:52:14
(4 months ago)
May 3 13:13:53 localhost kernel: [106173808.228858] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
May 3 13:13:53 localhost kernel: [106173808.228858] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=107.148.158.42 DST=[mungedIP2] LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=56489 PROTO=TCP SPT=48297 DPT=2087 WINDOW=1024 RES=0x00 SYN URGP=0
May 3 13:13:53 localhost kernel: [106173808.228879] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=107.148.158.42 DST=[mungedIP2] LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=56489 PROTO=TCP SPT=48297 DPT=2087 SEQ=207271152 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0
May 3 17:52:14 localhost kernel: [106190508.947720] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=107.148.158.42 DST=[mungedIP2] LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=52881 PROTO=TCP SPT=45055 DPT=2087 WINDOW=1024 RES=0x00 SYN URGP=0
May 3 17:52:14 localhost kernel: [106190508.947744] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=107.148.158.42 DST=[mungedIP2] LEN=40 TO
show less
Port Scan