๐ฎ๐ณ
evicky2002
2026-09-21 00:02:56
(5 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฎ๐น
CoreTech srl
2026-09-20 23:43:55
(5 days ago)
cloudlinux2 fail2ban: 2026-09-21 01:38:41,338 fail2ban.filter [1597]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-21 01:38:41,338 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 136.107.19.132 - 2026-09-21 01:38:41cloudlinux2 fail2ban: 2026-09-21 01:39:53,435 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 136.107.19.132 - 2026-09-21 01:39:53cloudlinux2 fail2ban: 2026-09-21 01:41:24,264 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 158.47.214.0 - 2026-09-21 01:41:23cloudlinux2 fail2ban: 2026-09-21 01:42:38,180 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 155.2.215.72 - 2026-09-21 01:42:38cloudlinux2 fail2ban: 2026-09-21 01:43:03,517 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 173.239.214.7 - 2026-09-21 01:43:02cloudlinux2 fail2ban: 2026-09-21 01:43:38,275 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 34.32.66.13 - 2026-09-21 01:43:38cloudlinux2 fail2ban: 2026-09-21 01:43:38,954 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 34.32.66.13 - 2026-09-21 01:43:38cloud
show less
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-20 23:28:34
(5 days ago)
Unauthorized access attempts:
[GET] /.git/config
UA: Unknown
Web App Attack
๐ฌ๐ท
setupgr
2026-09-20 23:28:23
(5 days ago)
(mod_security) mod_security (id:11000011) triggered by 136.107.19.132 (US/United States/District of ...
show more
(mod_security) mod_security (id:11000011) triggered by 136.107.19.132 (US/United States/District of Columbia/Washington/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:28:19.014809 2026] [security2:error] [pid 1025924:tid 1026093] [client 136.107.19.132:40046] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 132.19.107.136.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "www.gyrosplace.gr"] [uri "/.git/config"] [unique_id "arBsEyIiOWL33Dvd6JXD-wAAAc4"]
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-20 22:52:40
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 136.107.19.132 (132.19.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 136.107.19.132 (132.19.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:52:32.825995 2026] [security2:error] [pid 5523:tid 5523] [client 136.107.19.132:50642] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.gupta.net"] [uri "/.git/config"] [unique_id "arBjsPHogIG73iJF2snkyAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gumbysoft
2026-09-20 22:44:42
(5 days ago)
Unauthorized web vulnerability scan (/.env, wordpress, etc.)
Web App Attack
๐จ๐ฆ
polycoda
2026-09-20 22:33:13
(5 days ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
Anonymous
2026-09-20 22:26:22
(5 days ago)
136.107.19.132 - - [20/Sep/2026:19:26:20 -0300] "GET /.git/config HTTP/1.1" 403 829 "-" "-"
...
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-20 22:17:04
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.19.132 (132.19.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.19.132 (132.19.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:17:01.654992 2026] [security2:error] [pid 26857:tid 26857] [client 136.107.19.132:45020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.guarinofurnituredesigns.com"] [uri "/.git/config"] [unique_id "arBbXU2M-11Y-zEqR2-voAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-20 22:01:38
(5 days ago)
Auto-ban: >3000 req/min op 2026-09-20
Web App Attack
SSH
Hacking
๐ฎ๐น
Progetto1
2026-09-20 21:50:03
(5 days ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-09-20 21:50:03
(5 days ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:38:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.19.132 (132.19.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.19.132 (132.19.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:38:18.047664 2026] [security2:error] [pid 4944:tid 4944] [client 136.107.19.132:37452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grupoimaginarte.com"] [uri "/.git/config"] [unique_id "arBSSrr3CLTldwot9XqSdgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-20 21:20:06
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
Grossmann-Gruppe
2026-09-20 21:03:07
(5 days ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force