π«π·
Vaction
2026-08-24 08:06:48
(2 hours ago)
136.144.42.73 - - [24/Aug/2026:10:06:47 +0200] "GET /api/.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Wi ...
show more
136.144.42.73 - - [24/Aug/2026:10:06:47 +0200] "GET /api/.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
show less
Hacking
Bad Web Bot
Web App Attack
π©πͺ
iRaphi05
2026-08-23 10:30:55
(1 day ago)
Honeypot detection: GET request on /.env | User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537. ...
show more
Honeypot detection: GET request on /.env | User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 07:31:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 03:30:53.412470 2026] [security2:error] [pid 12714:tid 12714] [client 136.144.42.73:20749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.63"] [uri "/base/.env"] [unique_id "aoqhrbtgV_U-Y4LuyP2JJgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 12:31:50
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΈπ¬
Starburst SysOp Team
2026-08-22 11:44:19
(1 day ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-sin2-2)
Hacking
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-22 06:52:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:52:45.338435 2026] [security2:error] [pid 4011:tid 4011] [client 136.144.42.73:29829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.141"] [uri "/wp-admin/.env"] [unique_id "aolHPbX6-lx_WFO296wsAwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
neckaralb-admin.de
2026-08-21 20:59:15
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π«π·
Baking333
2026-08-21 18:26:10
(2 days ago)
[redacted] 136.144.42.73 - - [21/Aug/2026:19:26:08 +0100] "GET /[redacted] HTTP/1.1" 302 6758 0/5220 ...
show more
[redacted] 136.144.42.73 - - [21/Aug/2026:19:26:08 +0100] "GET /[redacted] HTTP/1.1" 302 6758 0/52203 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15" [redacted] 136.144.42.73 - - [21/Aug/2026:19:26:08 +0100] "GET /wp-admin/ HTTP/1.1" 301 5822 0/293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 15:27:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 11:27:50.898731 2026] [security2:error] [pid 26497:tid 26497] [client 136.144.42.73:30503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.215"] [uri "/wp-content/.env"] [unique_id "aohudnZArYHzKORoTeuLPQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 09:17:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 05:17:03.523249 2026] [security2:error] [pid 25008:tid 25008] [client 136.144.42.73:57837] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.166"] [uri "/local/.env"] [unique_id "aogXj4Rk1L4lBd1sdrjh7gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 08:54:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 04:53:35.053020 2026] [security2:error] [pid 26336:tid 26336] [client 136.144.42.73:20805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.87"] [uri "/new/.env"] [unique_id "aogSD6n4fhaKmMSlpb3K0gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 06:26:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 02:25:56.782021 2026] [security2:error] [pid 24763:tid 24763] [client 136.144.42.73:62255] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.136"] [uri "/.env"] [unique_id "aofvdJn4uT4zSbmiY-ViSgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 04:38:50
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 136.144.42.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 00:38:43.219597 2026] [security2:error] [pid 14483:tid 14483] [client 136.144.42.73:45765] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.240"] [uri "/backend/.env"] [unique_id "aofWU0TH-8qtc-ABa7ApDAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-08-21 04:03:39
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php
show less
Hacking
Web App Attack
π©πͺ
FeG Deutschland
2026-08-21 01:12:12
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack