๐ฉ๐ฐ
SaltySoftworks
2026-09-13 16:03:05
(2 days ago)
User agent spoofing
Page: /.htpasswd
Spoofing
Brute-Force
Web App Attack
Anonymous
2026-09-13 08:52:53
(2 days ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-13 08:30:29
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ฐ
SaltySoftworks
2026-09-13 08:09:00
(2 days ago)
Excessive requests
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-13 07:53:06
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-13 06:03:58
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-13 05:52:38
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.107.157.119 (119.157.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.107.157.119 (119.157.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 01:52:31.690718 2026] [security2:error] [pid 5819:tid 5819] [client 136.107.157.119:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||365soft.top|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "365soft.top"] [uri "/rclone.conf"] [unique_id "aqY6Hzy7T7fS4MbScP-AvAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
celestialcity
2026-09-13 03:38:54
(2 days ago)
Blocked by UFW on celestialcityas [8443/tcp] | SPT: 57632 | TTL: 50 | LEN: 60 | TOS: 0x00 โข Reported ...
show more
Blocked by UFW on celestialcityas [8443/tcp] | SPT: 57632 | TTL: 50 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-09-13 01:10:03
(2 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
dynamix
2026-09-12 22:15:02
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 07:18:01
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 136.107.157.119 (119.157.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.107.157.119 (119.157.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:17:57.412947 2026] [security2:error] [pid 12780:tid 12780] [client 136.107.157.119:58394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.koswerks.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.koswerks.net"] [uri "/rclone.conf"] [unique_id "aqT8pazUUptQl43zZ96xxQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Andrew
2026-09-11 18:50:57
(4 days ago)
136.107.157.119 - - [11/Sep/2026:19:50:56 +0100] "GET /backend/.env HTTP/1.1" 404 20278 "-" "Mozilla ...
show more
136.107.157.119 - - [11/Sep/2026:19:50:56 +0100] "GET /backend/.env HTTP/1.1" 404 20278 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
136.107.157.119 - - [11/Sep/2026:19:50:56 +0100] "GET /config/.env HTTP/1.1" 404 20277 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
136.107.157.119 - - [11/Sep/2026:19:50:56 +0100] "GET /Dockerfile HTTP/1.1" 404 18360 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
136.107.157.119 - - [11/Sep/2026:19:50:56 +0100] "GET /.github/.env HTTP/1.1" 404 18362 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
136.107.157.119 - - [11/Sep/2026:19:50:56 +0100] "GET /.git/config HTTP/1.1" 404 18361 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
136.107.157.119 - - [11/Sep/2026:19:50:57 +0100] "GET /.git/HEAD HTTP/1.1" 404 18359 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://
...
show less
Hacking
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-11 18:46:56
(4 days ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 18:40:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.157.119 (119.157.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.157.119 (119.157.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:39:58.506876 2026] [security2:error] [pid 10359:tid 10359] [client 136.107.157.119:55212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lorendata.net"] [uri "/.env"] [unique_id "aqRK_mSZnm-fPZD3ShpP0wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-11 18:38:24
(4 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack