๐บ๐ธ
TPI-Abuse
2026-08-26 23:14:16
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 142.111.152.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 142.111.152.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:13:30.587711 2026] [security2:error] [pid 13653:tid 13653] [client 142.111.152.129:63397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.43"] [uri "/app/config/.env"] [unique_id "ao9zGqat2ubSwIxnkuneewAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:49:16
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 142.111.152.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 142.111.152.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:48:46.809076 2026] [security2:error] [pid 4415:tid 4429] [client 142.111.152.129:53175] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.129"] [uri "/base/.env"] [unique_id "ao8Y7hC_uvzrkU5Ph4VGKwAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Halux
2026-08-26 15:35:19
(15 hours ago)
142.111.152.129 Probing protected path or service
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 08:07:14
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 142.111.152.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 142.111.152.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:06:55.219553 2026] [security2:error] [pid 32072:tid 32134] [client 142.111.152.129:53725] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.24"] [uri "/laravel/.env"] [unique_id "ao6enzH-mGsmjCKOCdOYHAAAAZM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
oalver
2026-08-24 16:19:21
(2 days ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-03. Risk score: 60/100.
show less
Web App Attack
๐ซ๐ฎ
YF
2026-08-23 17:00:34
(3 days ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
Anonymous
2026-08-22 13:29:01
(4 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob
2026-08-21 00:07:43
(6 days ago)
WordPress login brute-force | path: /wp-login.php
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-16 18:10:56
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-16 05:28:57
(1 week ago)
cloudlinux2 fail2ban: 2026-08-16 07:24:56,685 fail2ban.actions [1791]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-16 07:24:56,685 fail2ban.actions [1791]: NOTICE [plesk-modsecurity] Ban 182.70.183.136cloudlinux2 fail2ban: 2026-08-16 07:24:56,837 fail2ban.filter [1791]: INFO [recidive] Found 182.70.183.136 - 2026-08-16 07:24:56cloudlinux2 fail2ban: 2026-08-16 07:24:56,122 fail2ban.filter [1791]: INFO [plesk-modsecurity] Found 182.70.183.136 - 2026-08-16 07:24:56cloudlinux2 fail2ban: 2026-08-16 07:25:43,788 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 45.146.54.74 - 2026-08-16 07:25:41cloudlinux2 fail2ban: 2026-08-16 07:25:40,216 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 142.111.152.129 - 2026-08-16 07:25:38cloudlinux2 fail2ban: 2026-08-16 07:25:39,728 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 142.111.152.19 - 2026-08-16 07:25:38cloudlinux2 fail2ban: 2026-08-16 07:25:43,686 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 45.146.54.71 - 2026-08-16 07:25:41cloudlinux2 fail2ban: 2026-08-16
show less
FTP Brute-Force
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-08-16 03:54:21
(1 week ago)
attempted to access
Web App Attack
Anonymous
2026-08-06 19:21:11
(2 weeks ago)
Failed Wordpress Logins
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-05 13:55:10
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐น๐ท
oalver
2026-08-03 21:28:49
(3 weeks ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-03. Risk score: 30/100.
show less
Web App Attack
Anonymous
2026-08-02 19:48:16
(3 weeks ago)
Failed Wordpress Logins
Web App Attack