🇩🇪
neckaralb-admin.de
2026-08-24 15:42:37
(5 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇭🇰
azminawwar
2026-08-24 10:56:43
(5 days ago)
[136.144.42.78] triggered by honeypot on port [80], Timestamp [2026-08-24T10:56:42Z]METHOD=GET PATH= ...
show more
[136.144.42.78] triggered by honeypot on port [80], Timestamp [2026-08-24T10:56:42Z]METHOD=GET PATH=/blog/.env HTTP=HTTP/1.1 UA="Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chr
show less
Port Scan
Hacking
🇫🇮
YF
2026-08-24 04:00:35
(5 days ago)
WordPress author enumeration
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 20:30:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 16:30:21.740313 2026] [security2:error] [pid 26631:tid 26631] [client 136.144.42.78:44051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.245"] [uri "/apps/.env"] [unique_id "aotYXcjES0JHg7PWQrG48gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 18:47:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 14:47:31.765220 2026] [security2:error] [pid 3751:tid 3751] [client 136.144.42.78:58037] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.92"] [uri "/api/.env"] [unique_id "aotAQ7Lhi-hm1lUuu_pAiQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 15:22:24
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:21:46.657795 2026] [security2:error] [pid 31003:tid 31003] [client 136.144.42.78:35057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.11"] [uri "/api/.env"] [unique_id "aosQCvHmiSq9iNNOmwEKWgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇸
Smel
2026-08-23 04:37:05
(6 days ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 03:53:40
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:53:29.513652 2026] [security2:error] [pid 32585:tid 32585] [client 136.144.42.78:54217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.142"] [uri "/storage/.env"] [unique_id "aopuuc-UcNtsErHCzr3-XgAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 12:31:48
(1 week ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
jkhorvath.com
2026-08-22 11:53:40
(1 week ago)
Request for URL /audio/.env
Phishing
Brute-Force
Web App Attack
🇫🇮
geot
2026-08-22 09:56:58
(1 week ago)
GET /laravel/.env HTTP/1.1
Hacking
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-21 19:23:49
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 15:28:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 11:27:52.336794 2026] [security2:error] [pid 7805:tid 7805] [client 136.144.42.78:59155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.215"] [uri "/api/.env"] [unique_id "aohueMiTgKQv503KKw3mTAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 13:04:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 09:04:06.159503 2026] [security2:error] [pid 4856:tid 4856] [client 136.144.42.78:35407] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.72"] [uri "/wp-content/.env"] [unique_id "aohMxofCAVI-c2SLfQM9uAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 09:17:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 05:17:03.138174 2026] [security2:error] [pid 11560:tid 11560] [client 136.144.42.78:57961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.166"] [uri "/vendor/.env"] [unique_id "aogXj9Ux_xoQbzadvpDY1QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack