🇵🇱
dcnet
2026-09-06 06:00:18
(11 hours ago)
FortiGate detected DOS attack from IPv4 address 136.118.238.158
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:30
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:26.977287 2026] [security2:error] [pid 9176:tid 9176] [client 136.118.238.158:40552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sparemediagroup.com"] [uri "/wp-config.php~"] [unique_id "apzjPkKp08yjnVJpUfLe-AAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-06 03:21:32
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:18:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:18:23.761317 2026] [security2:error] [pid 1635:tid 1635] [client 136.118.238.158:39248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deharrisassoc.ltscatering.com"] [uri "/.env"] [unique_id "apzbf00aEbdn8fjtQmC-TgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-06 03:05:14
(14 hours ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
🇩🇪
FD-IX
2026-09-06 03:01:53
(14 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:56:58
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:56:54.075703 2026] [security2:error] [pid 257599:tid 257625] [client 136.118.238.158:34422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.malvadocuaderno.com"] [uri "/wp-config.php.bak"] [unique_id "apzWdh6CKJg02Y_H8XxU1QAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-09-06 02:26:10
(14 hours ago)
*Port Scan* detected from 136.118.238.158 (US/United States/Oregon/The Dalles/158.238.118.136.bc.goo ...
show more
*Port Scan* detected from 136.118.238.158 (US/United States/Oregon/The Dalles/158.238.118.136.bc.googleusercontent.com).
show less
Port Scan
🇬🇧
consul.to
2026-09-06 02:22:50
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-06 01:22:36
(15 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:10:08
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:10:03.887473 2026] [security2:error] [pid 13536:tid 13536] [client 136.118.238.158:51008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.globalmonitoringinc.com"] [uri "/.env.local"] [unique_id "apy9a8CDopLm6_7eWvrgxwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:21:38
(16 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:55:59
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.238.158 (158.238.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:55:51.412139 2026] [security2:error] [pid 27604:tid 27604] [client 136.118.238.158:33984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.baystarpartners.com"] [uri "/.env.production"] [unique_id "apysB24Oo0l1QdrCSsGzNwAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
todix
2026-09-05 23:49:38
(17 hours ago)
Web App Attack Exploid from 136.118.238.158
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-05 23:26:35
(17 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.118.238.158 (US/United States/158.238.118.1 ...
show more
(mod_security) mod_security (id:949110) triggered by 136.118.238.158 (US/United States/158.238.118.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack