🇩🇪
ger-stg-sifi1
2026-09-06 22:30:55
(37 minutes ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:01:24
(1 hour ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
Anonymous
2026-09-06 16:26:04
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.preprod HTTP/1.1, GET /.env.docker HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /.env.preprod HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.ci HTTP/1.1, GET /.env.remote HTTP/1.1, GET /.env.stage HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.live HTTP/1.1, GET /.env.example HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
kbeezie
2026-09-06 12:17:32
(10 hours ago)
136.83.52.154 - - [06/Sep/2026:08:17:31 -0400] "GET /tmp/phpinfo.php HTTP/1.1" 429 564 "-" "Mozilla/ ...
show more
136.83.52.154 - - [06/Sep/2026:08:17:31 -0400] "GET /tmp/phpinfo.php HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.83.52.154 - - [06/Sep/2026:08:17:31 -0400] "GET /public/phpinfo.php HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.83.52.154 - - [06/Sep/2026:08:17:31 -0400] "GET /info HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.83.52.154 - - [06/Sep/2026:08:17:31 -0400] "GET /phpversion.php HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.83.52.154 - - [06/Sep/2026:08:17:32 -0400] "GET /_phpinfo.php HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:10:50
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.83.52.154 (154.52.83.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.83.52.154 (154.52.83.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:10:43.376269 2026] [security2:error] [pid 23147:tid 23147] [client 136.83.52.154:48218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vangenderen.family.gabver.com"] [uri "/.git/config"] [unique_id "ap1YQ_E6sp-YBP2_3cH95AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 11:43:58
(11 hours ago)
10.690 requests with url.path *.env
1.089 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
🇮🇹
VHosting
2026-09-06 11:05:03
(12 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-06 10:32:19
(12 hours ago)
Scanning for web/db/file exploits on www.vanderhoutwestland.nl
SQL Injection
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-06 09:54:19
(13 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-06 08:52:39
(14 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-06 08:38:44
(14 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 06:47:37
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.83.52.154 (154.52.83.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.83.52.154 (154.52.83.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 02:47:30.218234 2026] [security2:error] [pid 18706:tid 18706] [client 136.83.52.154:41138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.valuerec.jmarkcapital.com"] [uri "/.git/config"] [unique_id "ap0MgsIsdz9yKG6uMMiXbgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 05:10:28
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.83.52.154 (154.52.83.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.83.52.154 (154.52.83.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:10:20.972038 2026] [security2:error] [pid 4696:tid 4696] [client 136.83.52.154:56034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "handyrehab.com"] [uri "/.git/config"] [unique_id "apz1vMoH9G_MI9pxBn9yHQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 05:02:08
(18 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:24:03
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.83.52.154 (154.52.83.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.83.52.154 (154.52.83.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:23:58.110773 2026] [security2:error] [pid 24839:tid 24839] [client 136.83.52.154:50010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "handymanhall.com"] [uri "/.git/config"] [unique_id "apzOvp1HTV9pwcBba66DZQAAAH4"]
show less
Brute-Force
Bad Web Bot
Web App Attack