๐จ๐ฆ
polycoda
2026-07-24 22:33:58
(2 hours ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐ฉ๐ช
gadix
2026-07-24 22:25:49
(2 hours ago)
[24/Jul/2026:21:37:38.140138 +0200] amO_ApxlBYNGWepXLfkEUgAAAAc 136.118.59.239 54896 127.0.0.1 7081
...
show more
[24/Jul/2026:21:37:38.140138 +0200] amO_ApxlBYNGWepXLfkEUgAAAAc 136.118.59.239 54896 127.0.0.1 7081
[24/Jul/2026:22:18:43.626495 +0200] amPIozb_xJwhVunDSAlRHwAAAAk 136.118.59.239 49476 127.0.0.1 7081
[25/Jul/2026:00:25:48.845883 +0200] amPmbOLzAz1n3m64diV8pgAAAAE 136.118.59.239 43502 127.0.0.1 7081
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-24 22:07:13
(2 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 136.118.59.239 (US/United States/23 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 136.118.59.239 (US/United States/239.59.118.136.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-07-24 22:04:41
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-24 21:03:08
(3 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
Anonymous
2026-07-24 21:02:53
(3 hours ago)
Unauthorized access (443/tcp/https)
Port Scan
Web App Attack
๐จ๐ญ
4server
2026-07-24 20:54:53
(3 hours ago)
[FriJul2422:54:47.3666342026][security2:error][pid767486:tid767714][client136.118.59.239:0]ModSecuri ...
show more
[FriJul2422:54:47.3666342026][security2:error][pid767486:tid767714][client136.118.59.239:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webmail.creazione-siti-ticino.ch\"][uri\"/.git/config\"][unique_id\"amPRF_qd_Awh55Xfq04fuQAAAJY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 20:38:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 16:38:49.346350 2026] [security2:error] [pid 208437:tid 208437] [client 136.118.59.239:45084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.convoyforkids.com"] [uri "/.git/config"] [unique_id "amPNWQOQEFREOKgIHRyUqAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-24 20:35:45
(4 hours ago)
csagent: score 17.1: 404 noise floor x7, secrets grab x7; 4 domain(s) in 42m3s
Web App Attack
๐ฉ๐ช
filstal.org
2026-07-24 20:26:57
(4 hours ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:56:51
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:56:45.152444 2026] [security2:error] [pid 4144098:tid 4144098] [client 136.118.59.239:60560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cinemastation.video"] [uri "/.git/config"] [unique_id "amPDfd5bxBOAxxcBqg7wlAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-24 19:40:24
(5 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 136.118.59.239 - - [24/Jul/2 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 136.118.59.239 - - [24/Jul/2026:22:40:24 +0300] "GET /.git/config HTTP/1.1" 403 2431 "-" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:37:33
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:37:25.714562 2026] [security2:error] [pid 1141208:tid 1141208] [client 136.118.59.239:46558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cfabeachblvd.com"] [uri "/.git/config"] [unique_id "amO-9SEDsaGHUk-fX6hRNQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:21:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:21:47.816676 2026] [security2:error] [pid 31123:tid 31123] [client 136.118.59.239:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.caspina.com"] [uri "/.git/config"] [unique_id "amO7S4lGG3xTtudUwk4yVQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:06:31
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.59.239 (239.59.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:06:25.974953 2026] [security2:error] [pid 2943166:tid 2943166] [client 136.118.59.239:43334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildcard.okwellbeing.com"] [uri "/.git/config"] [unique_id "amO3sVV7Oivx3lqU2IPY8AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack