π«π·
dynamix
2026-09-17 16:33:48
(7 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 16:27:09
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 135.136.51.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 135.136.51.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:27:02.496498 2026] [security2:error] [pid 27481:tid 27481] [client 135.136.51.240:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goalsnet.net"] [uri "/.env.nexkit-missing-135aef18e33772d910167d8a4b439b98"] [unique_id "aqwU1nCBNyIgfCR-AKoxbQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Baking333
2026-09-17 16:02:47
(8 hours ago)
[redacted] 135.136.51.240 - - [17/Sep/2026:17:02:46 +0100] "GET /.[redacted]-missing-ef1d12df8f6d461 ...
show more
[redacted] 135.136.51.240 - - [17/Sep/2026:17:02:46 +0100] "GET /.[redacted]-missing-ef1d12df8f6d4610f2cd91d4baeb3118 HTTP/1.1" 302 6773 0/43543 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:148.0) Gecko/20100101 Firefox/148.0" 443 [redacted] 135.136.51.240 - - [17/Sep/2026:17:02:46 +0100] "GET /.env HTTP/1.1" 302 6773 0/47938 "-" "Mozilla/5.0 (Linux; Android 15; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Mobile Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
π«π·
regishoussin
2026-09-17 15:51:09
(8 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-17 15:51 UTC.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 15:40:00
(8 hours ago)
apache vulnerability scan
Web App Attack
π©πͺ
conseilgouz
2026-09-17 15:05:54
(9 hours ago)
gie-17 : Block hidden directories=>/.env.nexkit-missing-4f3a2caba4c4d11f74e5bb00f65931d0(/)
Hacking
π§π·
dominioz
2026-09-17 13:35:51
(10 hours ago)
2026-09-17 13:35:19 GET /.env.nexkit-missing-6dcf7b0eda3ee045d6eaacc3d51ffccb - - 135.136.51.240 HTT ...
show more
2026-09-17 13:35:19 GET /.env.nexkit-missing-6dcf7b0eda3ee045d6eaacc3d51ffccb - - 135.136.51.240 HTTP/2 Mozilla/5.0+(Windows+NT+11.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/150.0.0.0+Safari/537.36 - 301 634
2026-09-17 13:35:19 GET /.env - - 135.136.51.240 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/152.0.0.0+Safari/537.36 - 301 538
2026-09-17 13:35:19 GET /.env.example - - 135.136.51.240 HTTP/2 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/147.0.0.0+Safari/537.36 - 301 554
2026-09-17 13:35:19 GET /.env.bak - - 135.136.51.240 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:147.0)+Gecko/20100101+Firefox/147.0 - 301 546
2026-09-17 13:35:21 GET /.env.production - - 135.136.51.240 HTTP/2 Mozilla/5.0+(Linux;+Android+15;+SM-S928B)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/146.0.0.0+Mobile+Safari/537.36 - 301 560
...
show less
Web App Attack
π³π±
Alt255
2026-09-17 10:28:04
(13 hours ago)
[ti-02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 135.136.51.240 - - [17/Sep/2026:12:27:55 +0200] "GET /.env.nexkit-missing-3b21e9f4d200b12f60dac4ff17d8d983 HTTP/2.0" 404 394 "-" "Mozilla/5.0 (Linux; Android 15; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π¬π§
Comberton
2026-09-17 10:22:54
(13 hours ago)
Ban via by F2B apache-wordfence jail
Brute-Force
πΊπΈ
lnklnx
2026-09-16 10:55:59
(1 day ago)
www.lincolnclan.com:443 135.136.51.240 - - [16/Sep/2026:05:55:57 -0500] "GET /.env.nexkit-missing-5e ...
show more
www.lincolnclan.com:443 135.136.51.240 - - [16/Sep/2026:05:55:57 -0500] "GET /.env.nexkit-missing-5e4d1e255d6e4de684700d4166857efe HTTP/1.1" 401 5576 "-" "Mozilla/5.0 (Linux; Android 15; SM-S928B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 10:17:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 135.136.51.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 135.136.51.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:16:57.771461 2026] [security2:error] [pid 24961:tid 24961] [client 135.136.51.240:58307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graduationpartynapkins.com"] [uri "/.env.nexkit-missing-ee3496ea02de0815e1015629dee877d5"] [unique_id "aqpsmaNT-4v_GqLXA_2cWQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 08:20:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 135.136.51.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 135.136.51.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:20:39.290882 2026] [security2:error] [pid 31929:tid 31929] [client 135.136.51.240:65465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kewlkarz.com"] [uri "/.env.nexkit-missing-775b7bb14918d2096c0126fbb4125a86"] [unique_id "aqpRVwEGlpu14u71a4IbNQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-16 04:46:42
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-16 04:32:05
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
πΊπΈ
TPI-Abuse
2026-09-16 03:00:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 135.136.51.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 135.136.51.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:00:51.877363 2026] [security2:error] [pid 26302:tid 26302] [client 135.136.51.240:59497] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arcdesign.me"] [uri "/.env.nexkit-missing-21bf1ce2b7f92dff3b78e85dda34d94d"] [unique_id "aqoGY5AfmF_b2r8Uz9STfwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack