🇮🇹
CoreTech srl
2026-09-12 02:58:56
(9 hours ago)
cloudlinux2 fail2ban: 2026-09-12 04:53:55,337 fail2ban.filter [1606]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-12 04:53:55,337 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 136.144.42.163 - 2026-09-12 04:53:54cloudlinux2 fail2ban: 2026-09-12 04:53:56,417 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 136.144.42.165 - 2026-09-12 04:53:55cloudlinux2 fail2ban: 2026-09-12 04:53:58,862 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 142.111.152.149 - 2026-09-12 04:53:58cloudlinux2 fail2ban: 2026-09-12 04:54:10,483 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 136.144.43.251 - 2026-09-12 04:54:06cloudlinux2 fail2ban: 2026-09-12 04:54:11,981 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 136.144.43.251 - 2026-09-12 04:54:11cloudlinux2 fail2ban: 2026-09-12 04:55:25,209 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Unban 14.192.215.211cloudlinux2 fail2ban: 2026-09-12 04:56:14,269 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 45.146.55.100 - 2026-09-12 04:56:13cloudlinux2 fail2ban:
show less
Web App Attack
Anonymous
2026-09-10 19:06:00
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇨🇭
Zdeněk Svancar
2026-08-25 21:33:41
(2 weeks ago)
136.144.42.163 - - [25/Aug/2026:21:33:39 +0000] "GET /api/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (W ...
show more
136.144.42.163 - - [25/Aug/2026:21:33:39 +0000] "GET /api/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
136.144.42.163 - - [25/Aug/2026:21:33:40 +0000] "GET /admin/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 07:21:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:21:32.663413 2026] [security2:error] [pid 23731:tid 23731] [client 136.144.42.163:31493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.90"] [uri "/wp-content/.env"] [unique_id "aovw_By9lurvdjcDMZxyNAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 01:11:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:10:52.068256 2026] [security2:error] [pid 22760:tid 22760] [client 136.144.42.163:32687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.50"] [uri "/api/.env"] [unique_id "aoJfnCd6s8wdgC4d3rEDzwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 23:34:45
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:34:19.050405 2026] [security2:error] [pid 17457:tid 17457] [client 136.144.42.163:38005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.250"] [uri "/www/.env"] [unique_id "aoJI-3QtXqFj5bdEYVEc1wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 16:09:18
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 12:08:57.858949 2026] [security2:error] [pid 5335:tid 5335] [client 136.144.42.163:29397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.92"] [uri "/new/.env"] [unique_id "aoHgmQ-ppwPeBrASRBw3iQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 12:48:28
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 08:48:15.479183 2026] [security2:error] [pid 18296:tid 18296] [client 136.144.42.163:33753] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.164"] [uri "/new/.env"] [unique_id "aoGxj7Us9E9uY6V65WvVjgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
azminawwar
2026-08-16 08:02:23
(3 weeks ago)
[136.144.42.163] triggered by honeypot on port [80], Timestamp [2026-08-16T08:02:23Z]METHOD=GET PATH ...
show more
[136.144.42.163] triggered by honeypot on port [80], Timestamp [2026-08-16T08:02:23Z]METHOD=GET PATH=/app/.env HTTP=HTTP/1.1 UA="Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chr
show less
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-08-16 06:05:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:05:05.444198 2026] [security2:error] [pid 6789:tid 6789] [client 136.144.42.163:41003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.103"] [uri "/conf/.env"] [unique_id "aoFTEZGUZyjFJANk8g0y_AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 02:09:08
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 22:08:32.524972 2026] [security2:error] [pid 9185:tid 9185] [client 136.144.42.163:46917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.148"] [uri "/src/.env"] [unique_id "aoEboLT_ay04E_gWkwURgAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
neron
2026-08-15 23:06:48
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 21:17:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 17:17:07.662089 2026] [security2:error] [pid 8368:tid 8368] [client 136.144.42.163:65057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.221"] [uri "/conf/.env"] [unique_id "aoDXU_n4a7_QKXj0n9KZgAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 20:59:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 16:59:01.606940 2026] [security2:error] [pid 14391:tid 14391] [client 136.144.42.163:21789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.46"] [uri "/wp-content/.env"] [unique_id "aoDTFWYS2SwMwGNbXcpeNgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
filstal.org
2026-08-15 20:04:01
(3 weeks ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack