π²πΎ
Rizzy
2026-08-28 19:33:32
(8 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 19:08:22
(34 minutes ago)
(mod_security) mod_security (id:949110) triggered by 136.115.40.224 (224.40.115.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 136.115.40.224 (224.40.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:08:15.338098 2026] [security2:error] [pid 32302:tid 32302] [client 136.115.40.224:55152] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "woodlandventures.com"] [uri "/wp-config.php~"] [unique_id "apHcn-YG6cCsKlC5hxmGSQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-28 18:45:40
(56 minutes ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π«π·
ELYAZ
2026-08-28 18:34:20
(1 hour ago)
(y3) Failed access -byebye- from 136.115.40.224 (US/United States/224.40.115.136.bc.googleuserconten ...
show more
(y3) Failed access -byebye- from 136.115.40.224 (US/United States/224.40.115.136.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
π©πͺ
tentwentyfour
2026-08-28 17:12:31
(2 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
π·π΄
iulianh
2026-08-28 17:07:22
(2 hours ago)
80,443
Brute-Force
SSH
π©πͺ
big-cloud.nl
2026-08-28 16:32:14
(3 hours ago)
Try to access /.env
Web App Attack
Anonymous
2026-08-28 16:30:05
(3 hours ago)
suspicious request in access.log
Web App Attack
π©πͺ
4server
2026-08-28 16:15:23
(3 hours ago)
[FriAug2818:15:21.4139782026][security2:error][pid2873809:tid2873873][client136.115.40.224:0]ModSecu ...
show more
[FriAug2818:15:21.4139782026][security2:error][pid2873809:tid2873873][client136.115.40.224:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"chryptofarm.ch.136-243-54-122.cpanel.site\"][uri\"/.env.old\"][unique_id\"apG0GfhBp3ryWgSGvCZx9gAAAII\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-08-28 16:13:15
(3 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 16:12:43
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.40.224 (224.40.115.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.40.224 (224.40.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:12:38.557960 2026] [security2:error] [pid 5919:tid 5919] [client 136.115.40.224:44828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verification.pazzidipizza.com"] [uri "/.env.local"] [unique_id "apGzdlh54Q_myuqlHiguagAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 15:39:39
(4 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.dimitrisanousis.com; logs=/var/log/httpd/domains/dimitri ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.dimitrisanousis.com; logs=/var/log/httpd/domains/dimitrisanousis.com.log; samples=/.env.local | /.env.dev | /.env.example
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 15:35:49
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.40.224 (224.40.115.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.40.224 (224.40.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:35:43.790235 2026] [security2:error] [pid 23731:tid 23731] [client 136.115.40.224:33936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.isyourcompanysafe.com"] [uri "/.env.old"] [unique_id "apGqz66bER83dZoQ6kuc-AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 15:27:12
(4 hours ago)
Banned by Fail2Ban on server
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-28 15:02:25
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking