๐ง๐พ
lns.bz
2026-08-21 23:03:27
(23 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 07:11:31
(1 day ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐พ
lns.bz
2026-08-19 20:57:19
(3 days ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-08-19 06:59:23
(3 days ago)
172.68.138.189 - - [19/Aug/2026:06:59:21 +0000] "GET /wp-includes/images/smilies/about.php HTTP/2.0" ...
show more
172.68.138.189 - - [19/Aug/2026:06:59:21 +0000] "GET /wp-includes/images/smilies/about.php HTTP/2.0" 404 3594 "-" "-" "20.169.136.165"
172.68.138.189 - - [19/Aug/2026:06:59:21 +0000] "GET /wp-mail.php HTTP/2.0" 404 3580 "-" "-" "20.169.136.165"
172.68.138.189 - - [19/Aug/2026:06:59:21 +0000] "GET /o.php HTTP/2.0" 404 3576 "-" "-" "20.169.136.165"
172.68.138.189 - - [19/Aug/2026:06:59:22 +0000] "GET /wp-admin/maint/admin.php HTTP/2.0" 404 3586 "-" "-" "20.169.136.165"
172.68.138.189 - - [19/Aug/2026:06:59:22 +0000] "GET /xmrlpc.php HTTP/2.0" 404 3581 "-" "-" "20.169.136.165"
172.68.138.189 - - [19/Aug/2026:06:59:22 +0000] "GET /file.php HTTP/2.0" 404 3578 "-" "-" "20.169.136.165"
172.68.138.189 - - [19/Aug/2026:06:59:22 +0000] "GET /wp-admin/css/index.php HTTP/2.0" 404 3586 "-" "-" "20.169.136.165"
172.68.138.189 - - [19/Aug/2026:06:59:23 +0000] "GET /wp-includes/style-engine/index.php HTTP/2.0" 404 3595 "-" "-" "20.169.136.165"
172.68.138.189 - - [19/Aug/2026:06:59:23 +0000] "GET /wp.p
...
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-17 10:42:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:42:47.993507 2026] [security2:error] [pid 2124:tid 2124] [client 172.68.138.189:13215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "the-jerks.flyingdodopublications.com"] [uri "/.git/HEAD"] [unique_id "aoLlp-wSnjs9kEcclXdofgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-17 00:58:06
(5 days ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:56:37
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:56:32.355637 2026] [security2:error] [pid 7801:tid 7801] [client 172.68.138.189:11073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.usfspirit.com"] [uri "/.git/config"] [unique_id "aoFfIAHz0qeBS0m77n13ygAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-08 16:35:06
(2 weeks ago)
Web App Attack
๐ฉ๐ช
acadeova
2026-07-25 16:07:37
(4 weeks ago)
๐จ Recon detected (nft drop)
SRC=172.68.138.189
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.138.189
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2026-06-22 13:31:38
(2 months ago)
LH-Watcher: FAKE_ID [Fake Bingbot]
Bad Web Bot
๐ฆ๐บ
trentwiles.com
2026-05-10 03:28:46
(3 months ago)
Unauthorized connection attempt detected from IP address 172.68.138.189 to port 2087 [SYD]
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-06 00:34:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 20:34:35.934660 2026] [security2:error] [pid 1513:tid 1516] [client 172.68.138.189:13860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.shieldsenterprisesusa.com"] [uri "/var/www/.env"] [unique_id "adL_m3Z1kVh_4tzm5JvvygAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 10:24:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 06:24:47.168987 2026] [security2:error] [pid 12150:tid 12150] [client 172.68.138.189:9632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rebelhollowfarm.com"] [uri "/.env.staging"] [unique_id "adI4b8KdfzYvpHhsyLa2sAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 17:38:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 13:38:26.552563 2026] [security2:error] [pid 30818:tid 30818] [client 172.68.138.189:13525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vesalappi.com"] [uri "/.env.production"] [unique_id "ac_7EhwSfV0-b5kZhGXcKgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 16:07:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 12:07:06.619985 2026] [security2:error] [pid 29315:tid 29315] [client 172.68.138.189:12193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achildsspace.com"] [uri "/.env.local"] [unique_id "ac_lqoG1ZGSj91uHgZKFkgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack