๐จ๐ฆ
Anytech
2026-09-16 18:17:39
(2 days ago)
Blocked by Conn-Monitor: Brute force activity
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-16 10:33:56
(2 days ago)
cloudlinux2 fail2ban: 2026-09-16 12:29:48,185 fail2ban.filter [1818]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-16 12:29:48,185 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 74.208.150.137 - 2026-09-16 12:29:48cloudlinux2 fail2ban: 2026-09-16 12:29:54,104 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 112.196.188.71 - 2026-09-16 12:29:53cloudlinux2 fail2ban: 2026-09-16 12:30:37,352 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 193.36.224.96 - 2026-09-16 12:30:36cloudlinux2 fail2ban: 2026-09-16 12:30:37,375 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 136.144.19.180 - 2026-09-16 12:30:36cloudlinux2 fail2ban: 2026-09-16 12:30:42,160 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 136.144.42.84 - 2026-09-16 12:30:41cloudlinux2 fail2ban: 2026-09-16 12:30:58,317 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 193.36.224.33 - 2026-09-16 12:30:58cloudlinux2 fail2ban: 2026-09-16 12:31:03,430 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 103.129.135.67 - 2026-09-16 12:31:0
show less
Web App Attack
Anonymous
2026-09-16 10:05:49
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
maxpower
2026-08-25 00:31:02
(3 weeks ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.144.42.84 (US/United States/-): 1 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.144.42.84 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.144.42.84 - - [25/Aug/2026:02:30:56 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 10422 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" "-" host=51.89.2.97
show less
Port Scan
๐ซ๐ฎ
geot
2026-08-22 09:56:42
(3 weeks ago)
GET /admin/.env HTTP/1.1
GET /app/.env HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 21:48:32
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:48:11.554290 2026] [security2:error] [pid 14372:tid 14372] [client 136.144.42.84:62859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.69"] [uri "/app/.env"] [unique_id "aojHm9QiOEST_VHKuo2-ZwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 19:50:44
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 15:50:19.160117 2026] [security2:error] [pid 18836:tid 18836] [client 136.144.42.84:36361] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.224"] [uri "/www/.env"] [unique_id "aoir-2L30c29kMntXGZWlAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 18:54:51
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 14:54:33.973244 2026] [security2:error] [pid 9413:tid 9413] [client 136.144.42.84:51147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.194"] [uri "/old/.env"] [unique_id "aoie6cTebjMLm_Hc08ol8wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 22:46:56
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 18:46:39.265410 2026] [security2:error] [pid 8935:tid 8952] [client 136.144.42.84:56031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.79"] [uri "/new/.env"] [unique_id "aoeDzwHgrOgAmF93A7MYLQAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
mnazibo
2026-08-14 13:15:13
(1 month ago)
Date: Aug 14 16:01:34 2026 EAT | Reported IP: 136.144.42.84 mod_security | id: 200002 | US/usernamea ...
show more
Date: Aug 14 16:01:34 2026 EAT | Reported IP: 136.144.42.84 mod_security | id: 200002 | US/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Failed to parse request body.
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
Vianpyro
2026-08-13 02:57:01
(1 month ago)
Honeypot: 10 request(s) in 0 min. Paths: /.env.prod, /_profiler, /_/debug, /config.yml, /config/smtp ...
show more
Honeypot: 10 request(s) in 0 min. Paths: /.env.prod, /_profiler, /_/debug, /config.yml, /config/smtp.yml. Method(s): GET. UA: python-httpx/0.28.1. ASN: 206092 (VPN Consumer Washington DC, United States).
show less
Web App Attack
Bad Web Bot
Hacking
๐บ๐ธ
whatda
2026-08-13 02:52:03
(1 month ago)
HTTP tarpit triggered at /.env.defaults. Scanner trapped for ~30s. UA: Mozilla/5.0
Bad Web Bot
Web App Attack
๐ฌ๐ง
neo101
2026-08-12 15:42:24
(1 month ago)
WordPress / Admin Brute-Force Probe: Automated scanner (WP Brute-Forcer) attempted admin login probe ...
show more
WordPress / Admin Brute-Force Probe: Automated scanner (WP Brute-Forcer) attempted admin login probe on static path '/wp-login.php'. Served DOM Crusher counter-measure.
show less
Hacking
Web App Attack
๐น๐ท
neron
2026-08-01 22:16:22
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-28 06:19:39
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack