๐จ๐ญ
zynex
2026-09-15 22:26:56
(1 day ago)
URL Probing: /index.php
Web App Attack
๐บ๐ธ
mnsf
2026-09-15 22:05:03
(1 day ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-15 22:02:52
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-15
Web App Attack
SSH
Hacking
๐ฉ๐ฐ
ScamAware
2026-09-15 20:03:03
(2 days ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot / scanner behavior). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: managed_challenge. Cloudflare source: botFight.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 19:50:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:50:20.635264 2026] [security2:error] [pid 3207:tid 3207] [client 20.164.136.197:4625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stewhist.org"] [uri "/.git/config"] [unique_id "aqmhfMBP5Zl3IszsskdkGwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:00:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:00:27.578001 2026] [security2:error] [pid 19106:tid 19106] [client 20.164.136.197:5634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.essav.net"] [uri "/.env.txt"] [unique_id "aqmVy5scRx80jWHL-pTgGgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:44:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:44:34.248027 2026] [security2:error] [pid 16032:tid 16032] [client 20.164.136.197:5637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webtony.net"] [uri "/.git/config"] [unique_id "aqmSEgjSuM1X64WBtTSCvwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:12:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:12:15.623777 2026] [security2:error] [pid 17631:tid 17631] [client 20.164.136.197:4621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.taylorandatlantic.net"] [uri "/.git/config"] [unique_id "aqmKf7mSG-ies_stgDo9-wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:54:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:54:29.429912 2026] [security2:error] [pid 15143:tid 15143] [client 20.164.136.197:5713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.celltechs.net"] [uri "/.env.txt"] [unique_id "aqmGVWzBI36j16MfxL6y_AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:38:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.164.136.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:38:20.825434 2026] [security2:error] [pid 25180:tid 25180] [client 20.164.136.197:5648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fibroscopie.net"] [uri "/.env.txt"] [unique_id "aqmCjG8kdDyavA4Dh1oiNAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-09-15 17:03:50
(2 days ago)
http-sensitive-files - IP: 20.164.136.197 - time="2026-09-15T19:03:50+02:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 20.164.136.197 - time="2026-09-15T19:03:50+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 20.164.136.197 (ZA/8075) : 4h ban on Ip 20.164.136.197" module=db
show less
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-15 16:01:48
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from ZA.
Action taken: BLOCK
ASN: 8075 (Microsoft Corporat ...
show more
Triggered Cloudflare WAF (firewallCustom) from ZA.
Action taken: BLOCK
ASN: 8075 (Microsoft Corporation)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-15T10:38:56Z
Ray ID: a3b70135ee3593cc
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-09-15 14:25:02
(2 days ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-15 14:08:02
(2 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01]
Hacking
SQL Injection
Web App Attack
Anonymous
2026-09-15 13:51:00
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack