๐บ๐ธ
TPI-Abuse
2026-08-21 12:23:11
(7 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 08:23:05.529721 2026] [security2:error] [pid 17994:tid 18014] [client 136.144.42.70:53319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.125"] [uri "/vendor/.env"] [unique_id "aohDKV0OjuRpM-CJc_dEmwAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Zdenฤk Svancar
2026-08-21 12:07:54
(23 minutes ago)
136.144.42.70 - - [21/Aug/2026:12:07:51 +0000] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Window ...
show more
136.144.42.70 - - [21/Aug/2026:12:07:51 +0000] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
136.144.42.70 - - [21/Aug/2026:12:07:53 +0000] "GET /library/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 10:45:49
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:45:46.312643 2026] [security2:error] [pid 11420:tid 11420] [client 136.144.42.70:49609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.186"] [uri "/local/.env"] [unique_id "aogsWmbdAmKN7Xdc6wm5owAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 09:17:15
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 05:17:02.571613 2026] [security2:error] [pid 2162:tid 2162] [client 136.144.42.70:56159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.166"] [uri "/wp-admin/.env"] [unique_id "aogXjpqV1mmw2m7uh2C0gwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 03:59:20
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 23:58:55.359898 2026] [security2:error] [pid 32123:tid 32123] [client 136.144.42.70:22205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.144"] [uri "/app/.env"] [unique_id "aofM_9HJKSGvdHLgcaVNWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-08-21 02:00:29
(10 hours ago)
WordPress author enumeration
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-21 01:59:39
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-17 13:03:57
(3 days ago)
cloudlinux2 fail2ban: 2026-08-17 14:58:52,897 fail2ban.filter [1456]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-17 14:58:52,897 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 91.193.232.88 - 2026-08-17 14:58:52cloudlinux2 fail2ban: 2026-08-17 14:59:42,774 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 91.193.232.243 - 2026-08-17 14:59:41cloudlinux2 fail2ban: 2026-08-17 14:59:42,391 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 173.239.213.19 - 2026-08-17 14:59:41cloudlinux2 fail2ban: 2026-08-17 15:00:24,548 fail2ban.actions [1456]: NOTICE [plesk-modsecurity] Unban 136.67.129.228cloudlinux2 fail2ban: 2026-08-17 15:00:39,034 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 45.8.19.154 - 2026-08-17 15:00:38cloudlinux2 fail2ban: 2026-08-17 15:00:38,808 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 45.8.19.177 - 2026-08-17 15:00:38cloudlinux2 fail2ban: 2026-08-17 15:00:48,209 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 136.144.42.80 - 2026-08-17 15:00:47cloudlinux2 fail2ban: 2026-08-
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-16 09:24:23
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐น๐ท
neron
2026-08-15 23:06:48
(5 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-13 09:38:56
(1 week ago)
cloudlinux2 fail2ban: 2026-08-13 11:33:56,720 fail2ban.filter [1463]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-13 11:33:56,720 fail2ban.filter [1463]: INFO [plesk-modsecurity] Found 39.34.232.140 - 2026-08-13 11:33:56cloudlinux2 fail2ban: 2026-08-13 11:34:45,532 fail2ban.filter [1463]: INFO [plesk-modsecurity] Found 103.48.145.212 - 2026-08-13 11:34:45cloudlinux2 fail2ban: 2026-08-13 11:35:44,290 fail2ban.actions [1463]: NOTICE [plesk-modsecurity] Unban 180.252.175.217cloudlinux2 fail2ban: 2026-08-13 11:35:44,858 fail2ban.filter [1463]: INFO [plesk-wordpress] Found 136.144.42.70 - 2026-08-13 11:35:44cloudlinux2 fail2ban: 2026-08-13 11:35:59,450 fail2ban.filter [1463]: INFO [plesk-modsecurity] Found 103.48.145.212 - 2026-08-13 11:35:59cloudlinux2 fail2ban: 2026-08-13 11:36:20,951 fail2ban.actions [1463]: NOTICE [plesk-modsecurity] Ban 103.48.145.212cloudlinux2 fail2ban: 2026-08-13 11:36:20,957 fail2ban.filter [1463]: INFO [recidive] Found 103.48.145.212 - 2026-08-13 11:36:20cloudlinux2 fail2ban: 2026-08-13 11:36:20,616
show less
Web App Attack
๐น๐ท
neron
2026-08-06 06:29:42
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-01 22:16:22
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
Anonymous
2026-07-29 05:51:02
(3 weeks ago)
Fail2Ban - Wordpress brute-force
...
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-20 16:42:46
(1 month ago)
Try to access /xmlrpc.php
Web App Attack