Anonymous
2026-06-25 13:18:38
(19 hours ago)
Port scan and brute force attack
Port Scan
Brute-Force
Anonymous
2026-06-25 07:10:47
(1 day ago)
"GET /.aws/credentials HTTP/1.1"
Hacking
Web App Attack
๐ฉ๐ช
ITSNF
2026-06-25 06:25:02
(1 day ago)
Blocked by os-abuseipdb; 14 hits, proto=tcp, ports=443,80
Port Scan
Hacking
๐ฉ๐ช
Petros Stefanakis
2026-06-24 10:12:27
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 142.248.80.182 (US/United States/-)
SQL Injection
๐ง๐ช
taivas.nl
2026-06-24 07:02:12
(2 days ago)
Site scraper
Web App Attack
๐ซ๐ท
masterguru
2026-06-24 05:09:12
(2 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 142.248.80.182 (US/United States/-): ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 142.248.80.182 (US/United States/-): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ฉ๐ช
SwinT
2026-06-23 21:00:03
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-23 20:43:12
(2 days ago)
142.248.80.182 - - [23/Jun/2026:23:43:11 +0300] "GET /wp-content/debug.log HTTP/1.1" 404 709 "-" "Mo ...
show more
142.248.80.182 - - [23/Jun/2026:23:43:11 +0300] "GET /wp-content/debug.log HTTP/1.1" 404 709 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0"
...
show less
Web App Attack
Anonymous
2026-06-23 18:05:11
(2 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 17:42:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 142.248.80.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 142.248.80.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 13:42:51.902682 2026] [security2:error] [pid 14543:tid 14543] [client 142.248.80.182:38372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.michaelandkatie.us"] [uri "/.env.production.copy"] [unique_id "ajrFm_wm5Uzz2m-jlSptrAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-23 16:41:40
(2 days ago)
142.248.80.182 - - [23/Jun/2026:19:41:39 +0300] "GET /api/.env HTTP/1.1" 404 778 "-" "Mozilla/5.0 (M ...
show more
142.248.80.182 - - [23/Jun/2026:19:41:39 +0300] "GET /api/.env HTTP/1.1" 404 778 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ต๐ฑ
lns.bz
2026-06-23 15:39:55
(2 days ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
Anonymous
2026-06-23 14:39:07
(2 days ago)
142.248.80.182 - - [23/Jun/2026:09:39:07 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
142.248.80.182 - - [23/Jun/2026:09:39:07 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:150.0) Gecko/20100101 Firefox/150.0" 142.248.80.182
142.248.80.182 - - [23/Jun/2026:09:39:07 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36" 142.248.80.182
142.248.80.182 - - [23/Jun/2026:09:39:07 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36" 142.248.80.182
142.248.80.182 - - [23/Jun/2026:09:39:07 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0" 142.248.80.182
142.248.80.182 - - [23/Jun/2026:09:39:07 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.0) Gecko/20100101 Firefox/150.0" 142.248.80.182
142.248.80.182 - - [23/Ju
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
pixiekat
2026-06-23 13:20:44
(2 days ago)
[Tue Jun 23 13:20:39.651012 2026] [access_compat:error] [pid 283398:tid 283403] [client 142.248.80.1 ...
show more
[Tue Jun 23 13:20:39.651012 2026] [access_compat:error] [pid 283398:tid 283403] [client 142.248.80.182:41754] AH01797: client denied by server configuration: /var/www/vhosts/infosage-api/public/
[Tue Jun 23 13:20:41.105613 2026] [access_compat:error] [pid 283398:tid 283425] [client 142.248.80.182:41754] AH01797: client denied by server configuration: /var/www/vhosts/infosage-api/public/wp-content
[Tue Jun 23 13:20:41.154786 2026] [access_compat:error] [pid 283398:tid 283409] [client 142.248.80.182:41764] AH01797: client denied by server configuration: /var/www/vhosts/infosage-api/public/, referer: http://dev.infosagehealth.org/
[Tue Jun 23 13:20:43.297656 2026] [access_compat:error] [pid 283398:tid 283424] [client 142.248.80.182:41754] AH01797: client denied by server configuration: /var/www/vhosts/infosage-api/public/.env
[Tue Jun 23 13:20:44.162506 2026] [access_compat:error] [pid 283400:tid 283439] [client 142.248.80.182:42144] AH01797: client denied by server configuration: /var/ww
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-23 13:02:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 142.248.80.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 142.248.80.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 09:02:54.084021 2026] [security2:error] [pid 7443:tid 7443] [client 142.248.80.182:44664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lavozdemurcia.murciafm.com"] [uri "/.env~"] [unique_id "ajqD_qF_rOdl6XF8dKVLpAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack