🇿🇦
conure.sh
2026-09-10 12:10:19
(4 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 1s
Web App Attack
🇳🇱
debestelapp
2026-09-10 06:05:14
(10 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 05:14:35
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 01:14:30.383119 2026] [security2:error] [pid 18886:tid 18886] [client 136.107.121.139:54498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sasquatchproductionsltd.com"] [uri "/.git/config"] [unique_id "aqI8thZNabUugYC5dyiNwgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-10 03:05:24
(13 hours ago)
Too many Status 50X (170)
Scanning/Probing (134)
Request Overload (170)
Brute-Force
Web App Attack
🇳🇱
ConsulHosting
2026-09-10 00:58:05
(15 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇫🇷
regishoussin
2026-09-09 21:32:57
(19 hours ago)
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-09 21:32 UTC.
show less
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 21:18:57
(19 hours ago)
cloudlinux2 fail2ban: 2026-09-09 23:14:27,359 fail2ban.filter [1892]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-09 23:14:27,359 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 172.98.33.102 - 2026-09-09 23:14:26cloudlinux2 fail2ban: 2026-09-09 23:14:27,358 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 172.98.33.124 - 2026-09-09 23:14:26cloudlinux2 fail2ban: 2026-09-09 23:14:45,937 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 142.111.152.103 - 2026-09-09 23:14:45cloudlinux2 fail2ban: 2026-09-09 23:16:48,277 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 136.107.121.139 - 2026-09-09 23:16:48cloudlinux2 fail2ban: 2026-09-09 23:16:48,130 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 136.107.121.139cloudlinux2 fail2ban: 2026-09-09 23:16:48,500 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 136.107.121.139 - 2026-09-09 23:16:48cloudlinux2 fail2ban: 2026-09-09 23:16:47,940 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 136.107.121.139 - 2026-09-09 23:16:47cloudlinux2 fai
show less
Web App Attack
🇧🇪
cmbplf
2026-09-09 20:28:42
(20 hours ago)
4.579 requests with url.path *.env
645 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 20:08:32
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:08:27.620614 2026] [security2:error] [pid 2668521:tid 2668696] [client 136.107.121.139:50498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saskiarose.com"] [uri "/.git/config"] [unique_id "aqG8u2IAPLtaD96edHtwCwAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 19:05:03
(21 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 17:58:40
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 13:58:32.354627 2026] [security2:error] [pid 25454:tid 25461] [client 136.107.121.139:33408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sasintegrated.com"] [uri "/.git/config"] [unique_id "aqGeSLxiup_eURSoGbLXKQAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 16:33:27
(1 day ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:54:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:54:18.122550 2026] [security2:error] [pid 23523:tid 23523] [client 136.107.121.139:48618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nmposters.com"] [uri "/.git/config"] [unique_id "aqFW-nNbn58CCoYz1AUtOQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 12:54:12
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:06:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.139 (139.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:05:54.834016 2026] [security2:error] [pid 1373055:tid 1373055] [client 136.107.121.139:49444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nmorganist.org"] [uri "/.git/config"] [unique_id "aqFLonQyGZXYrqjEGOpZqgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack