Anonymous
2026-09-03 07:58:14
(6 days ago)
Failed Wordpress Logins
Web App Attack
🇩🇪
schuh
2026-08-25 07:52:48
(2 weeks ago)
25-08-2026:07:51:45UTC [Caddy] Suspicious web request: uri:/laravel/.env,/vendor/laravel/.env (2 req ...
show more
25-08-2026:07:51:45UTC [Caddy] Suspicious web request: uri:/laravel/.env,/vendor/laravel/.env (2 requests) tcp:80
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 22:53:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 18:53:24.114338 2026] [security2:error] [pid 5325:tid 5325] [client 136.144.42.189:22987] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.65"] [uri "/new/.env"] [unique_id "aozLZLxciwqm5QEYJZtWjQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 23:02:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 19:02:23.835345 2026] [security2:error] [pid 12650:tid 12650] [client 136.144.42.189:54487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.27"] [uri "/protected/.env"] [unique_id "aojY_8bXsbQYI7egDXfvRAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Security_Whaller
2026-08-21 22:33:47
(2 weeks ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 21:42:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:42:42.203880 2026] [security2:error] [pid 20816:tid 20816] [client 136.144.42.189:21291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.184"] [uri "/conf/.env"] [unique_id "aojGUn3yGaXcu06QEtbPZQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 19:50:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 15:50:14.791707 2026] [security2:error] [pid 9689:tid 9689] [client 136.144.42.189:29691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.224"] [uri "/new/.env"] [unique_id "aoir9tIX0o4p7u_MXN00mQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
wimaxnz
2026-08-21 02:36:14
(2 weeks ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
🇺🇸
TPI-Abuse
2026-08-21 01:11:22
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 21:11:12.693190 2026] [security2:error] [pid 24130:tid 24130] [client 136.144.42.189:45681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.101"] [uri "/old/.env"] [unique_id "aoelsN94ONWf89W9TaMv4gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 00:15:00
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 20:14:46.313757 2026] [security2:error] [pid 5380:tid 5380] [client 136.144.42.189:65205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.197"] [uri "/core/.env"] [unique_id "aoeYdtp4KCl5saTdKfPeMQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 23:28:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 19:28:23.916903 2026] [security2:error] [pid 6295:tid 6295] [client 136.144.42.189:43483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.251"] [uri "/crm/.env"] [unique_id "aoeNl4FPScNWcgz1tPwsIwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 22:46:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 18:46:39.450350 2026] [security2:error] [pid 23397:tid 23417] [client 136.144.42.189:22965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.79"] [uri "/vendor/.env"] [unique_id "aoeDz0dOqA7z0n7zy5z_HwAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 22:20:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 18:19:58.506623 2026] [security2:error] [pid 24347:tid 24382] [client 136.144.42.189:38313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.23"] [uri "/sites/all/libraries/mailchimp/.env"] [unique_id "aod9jqGM9TT_YLVJc8EpAgAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
neron
2026-08-15 09:06:48
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇺🇸
whatda
2026-08-13 04:46:00
(3 weeks ago)
HTTP tarpit triggered at /.github/secrets.yml. Scanner trapped for ~30s. UA: python-httpx/0.28.1
Bad Web Bot
Web App Attack