๐บ๐ธ
dot.mg
2026-09-16 08:28:13
(1 day ago)
Scan of vulnerable files
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 04:40:02
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:14:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.149.40 (40.149.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.149.40 (40.149.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:13:56.961890 2026] [security2:error] [pid 15916:tid 15916] [client 136.85.149.40:34880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tradesecretintrust.com"] [uri "/.git/config"] [unique_id "aqmY9BlQN_SY280lfoh4DgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:24:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.149.40 (40.149.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.149.40 (40.149.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:24:40.436930 2026] [security2:error] [pid 16367:tid 16367] [client 136.85.149.40:55572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tradenaples.com"] [uri "/.git/config"] [unique_id "aql_WEYWHILo9Kw7cRsByQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
akasolutions.de
2026-09-15 15:04:25
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 136.85.149.40 (US/United States/40.149. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.85.149.40 (US/United States/40.149.85.136.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
kivitendo.de
2026-09-15 12:47:22
(2 days ago)
[Tue Sep 15 14:47:27.232696 2026] [access_compat:error] [pid 220854:tid 220878] [client 136.85.149.4 ...
show more
[Tue Sep 15 14:47:27.232696 2026] [access_compat:error] [pid 220854:tid 220878] [client 136.85.149.40:49140] AH01797: client denied by server configuration: /var/www/kivitendo-erp/.git/config
[Tue Sep 15 14:47:33.264623 2026] [access_compat:error] [pid 220854:tid 220860] [client 136.85.149.40:49140] AH01797: client denied by server configuration: /var/www/kivitendo-erp/config/.env
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
marten_o
2026-09-15 12:42:14
(2 days ago)
136.85.149.40 - - [15/Sep/2026:14:42:13 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 573 "-" "Mozilla/ ...
show more
136.85.149.40 - - [15/Sep/2026:14:42:13 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 573 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 314 771
...
show less
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-15 07:07:33
(3 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ญ๐บ
miszterx.hu
2026-09-15 06:44:59
(3 days ago)
XORP (haproxy): 139x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_i ...
show more
XORP (haproxy): 139x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ฉ๐ช
NewWavesApp
2026-09-15 04:27:48
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 136.85.149.40 (US/United States/40.149. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.85.149.40 (US/United States/40.149.85.136.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ฉ๐ช
zumbo.net
2026-09-15 03:59:36
(3 days ago)
[Tue Sep 15 06:59:34.645185 2026] [proxy_fcgi:error] [pid 476949:tid 476958] [client 136.85.149.40:0 ...
show more
[Tue Sep 15 06:59:34.645185 2026] [proxy_fcgi:error] [pid 476949:tid 476958] [client 136.85.149.40:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 15 06:59:34.805960 2026] [proxy_fcgi:error] [pid 476951:tid 476992] [client 136.85.149.40:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 15 06:59:34.962831 2026] [proxy_fcgi:error] [pid 476951:tid 476963] [client 136.85.149.40:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 15 06:59:35.118577 2026] [proxy_fcgi:error] [pid 476951:tid 476996] [client 136.85.149.40:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 15 06:59:35.273935 2026] [proxy_fcgi:error] [pid 476949:tid 476961] [client 136.85.149.40:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 01:50:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack