๐ช๐ธ
alferez
2026-09-01 11:12:55
(4 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 11:11:54
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 11:01:17
(5 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ต๐ฑ
Woytass
2026-09-01 10:45:13
(5 hours ago)
CSF/lfd permanent block on srv1.woytas.ovh. Trigger=LF_MODSEC; ports=*; (mod_security) mod_security ...
show more
CSF/lfd permanent block on srv1.woytas.ovh. Trigger=LF_MODSEC; ports=*; (mod_security) mod_security (id:949110) triggered by 136.66.208.187 (US/United States/187.208.66.136.bc.googleusercontent.com): 5 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:57:18
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:57:09.992433 2026] [security2:error] [pid 24935:tid 24935] [client 136.66.208.187:36918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fatjesus.com.sparler.com"] [uri "/wp-config.php.bak"] [unique_id "apahdZm6IYBMbgcRUr2QRAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 09:35:02
(6 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
Rip
2026-09-01 08:29:22
(7 hours ago)
Automated reconnaissance against web infrastructure.
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 07:05:28
(8 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:08:23
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:08:15.280851 2026] [security2:error] [pid 20108:tid 20108] [client 136.66.208.187:50690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michaelhick.com"] [uri "/wp-config.php.swp"] [unique_id "apZrzz5CcmwGAOYWTUitfwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:06:26
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:06:23.089959 2026] [security2:error] [pid 11133:tid 11133] [client 136.66.208.187:47224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.accu-tuner.com"] [uri "/.env.example"] [unique_id "apZdTyHxHCz8a13xIKlEXAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:00:49
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:00:44.317877 2026] [security2:error] [pid 9582:tid 9582] [client 136.66.208.187:46452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadek.com"] [uri "/.env.example"] [unique_id "apZN7AOyEA8BI4_lhwxBlgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-09-01 03:46:25
(12 hours ago)
(nginxENVSCAN) nginx environment-file scanner detected from 136.66.208.187 (US/United States/Oregon/ ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 136.66.208.187 (US/United States/Oregon/The Dalles/187.208.66.136.bc.googleusercontent.com)
show less
Hacking
๐ฉ๐ช
ITSNF
2026-09-01 03:15:03
(12 hours ago)
Blocked by os-abuseipdb; 76 hits, proto=tcp, ports=443,80
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 02:44:29
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.208.187 (187.208.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:44:21.882454 2026] [security2:error] [pid 4878:tid 4878] [client 136.66.208.187:34454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.citystreetsalon.com"] [uri "/wp-config.php~"] [unique_id "apY8BbAMMBeAdie4Tr0CYAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 02:35:30
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.66.208.187 (US/United States/187.208.66.136 ...
show more
(mod_security) mod_security (id:949110) triggered by 136.66.208.187 (US/United States/187.208.66.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack