Anonymous
2026-08-27 22:01:28
(4 hours ago)
Blocked by firewall on hugin [8081/tcp] | Rule: AbuseIPDB | SPT: 44912 | TTL: 57 | LEN: 60 | TOS: 0x ...
show more
Blocked by firewall on hugin [8081/tcp] | Rule: AbuseIPDB | SPT: 44912 | TTL: 57 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ป๐ณ
trung.fun
2026-08-27 21:31:31
(4 hours ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
๐ง๐ท
noconex
2026-08-27 21:20:03
(4 hours ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 34.148.136.243
show less
Port Scan
Brute-Force
SSH
๐ฉ๐ช
yvoictra
2026-08-27 20:52:03
(5 hours ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 19:05:15
(7 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-27 18:53:58
(7 hours ago)
cloudlinux2 fail2ban: 2026-08-27 20:48:56,170 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-27 20:48:56,170 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 154.192.250.135 - 2026-08-27 20:48:56cloudlinux2 fail2ban: 2026-08-27 20:48:56,882 fail2ban.filter [1775]: INFO [recidive] Found 154.192.250.135 - 2026-08-27 20:48:56cloudlinux2 fail2ban: 2026-08-27 20:48:56,681 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Ban 154.192.250.135cloudlinux2 fail2ban: 2026-08-27 20:50:14,902 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 172.68.174.254 - 2026-08-27 20:50:14cloudlinux2 fail2ban: 2026-08-27 20:50:14,917 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 172.68.174.151 - 2026-08-27 20:50:14cloudlinux2 fail2ban: 2026-08-27 20:50:22,412 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.148.136.243 - 2026-08-27 20:50:22cloudlinux2 fail2ban: 2026-08-27 20:50:22,445 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.148.136.243 - 2026-08-27 20:50:22cloudlinux2 fail2b
show less
Brute-Force
๐ฉ๐ช
dom4k
2026-08-27 18:48:57
(7 hours ago)
34.148.136.243 - - [27/Aug/2026:18:48:56 +0000] "GET /.env.bak HTTP/1.1" 444 0 "-" "crusader-worker/ ...
show more
34.148.136.243 - - [27/Aug/2026:18:48:56 +0000] "GET /.env.bak HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:33:42
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.136.243 (243.136.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.136.243 (243.136.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:33:35.354657 2026] [security2:error] [pid 28727:tid 28727] [client 34.148.136.243:60626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.namisushionline.com"] [uri "/wp-config.php.swp"] [unique_id "apCC_-u4fQ3QVh8wYxe-1gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-27 18:20:14
(7 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-27 18:18:58
(7 hours ago)
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4504 "-" "crusade ...
show more
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4504 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4503 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /.env.dev HTTP/1.1" 404 4504 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /actuator/configprops HTTP/1.1" 404 4504 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 4504 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /.env.production HTTP/1.1" 404 4503 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /actuator/env HTTP/1.1" 404 4504 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /.env.local HTTP/1.1" 404 4504 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:20:18:56 +0200] "GET /wp-config.php.swp HTTP/1.1
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-27 17:18:16
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.136.243 (243.136.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.136.243 (243.136.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:18:12.018840 2026] [security2:error] [pid 23723:tid 23723] [client 34.148.136.243:52822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web103.dnchosting.com"] [uri "/.env"] [unique_id "apBxVBblOxha3-MBc5vd5wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-08-27 16:48:09
(9 hours ago)
Web app vulnerability scanning detected. Evidence: 34.148.136.243 - - [27/Aug/2026:16:48:06 +0000] " ...
show more
Web app vulnerability scanning detected. Evidence: 34.148.136.243 - - [27/Aug/2026:16:48:06 +0000] "GET /.env.save HTTP/1.1" 404 50082 "-" "crusader-worker/1.0"
34.148.136.243 - - [27/Aug/2026:16:48:06 +0000] "GET /.env.dev HTTP/1.1" 404 50080 "-" "crusader-worker/1.0"
show less
Web App Attack
๐บ๐ธ
Copious7283
2026-08-27 16:34:04
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
cg-design.co.uk
2026-08-27 15:46:42
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.148.136.243 (US/United States/243.13 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.148.136.243 (US/United States/243.136.148.34.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
dynamix
2026-08-27 15:25:51
(10 hours ago)
Multiple WAF Violations
Web App Attack