🇺🇸
TPI-Abuse
2026-09-11 19:14:01
(5 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.107.121.250 (250.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210580) triggered by 136.107.121.250 (250.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:13:55.011423 2026] [security2:error] [pid 31324:tid 31324] [client 136.107.121.250:43674] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||intelligent-design.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "intelligent-design.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqRS8xkw35nKUNYf-1YsrAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 19:09:26
(5 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-11 18:58:18
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.250 (250.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.250 (250.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:58:13.164391 2026] [security2:error] [pid 470139:tid 470139] [client 136.107.121.250:54182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infinitynull.net"] [uri "/@fs/.env"] [unique_id "aqRPRSPWha6kE52qMqxoAQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:21:50
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.250 (250.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.250 (250.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:21:44.241267 2026] [security2:error] [pid 26792:tid 26792] [client 136.107.121.250:57386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagea.net"] [uri "/api/.env"] [unique_id "aqRGuAJUjsfvobUznYccogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-11 18:20:22
(6 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-11 18:18:57
(6 hours ago)
136.107.121.250 - - [11/Sep/2026:20:18:54 +0200] "GET /.env?raw HTTP/2.0" 404 295 "-" "Mozilla/5.0 ( ...
show more
136.107.121.250 - - [11/Sep/2026:20:18:54 +0200] "GET /.env?raw HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
136.107.121.250 - - [11/Sep/2026:20:18:54 +0200] "GET /files../.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; Bytespider; [email]) AppleWebKit/537.36"
136.107.121.250 - - [11/Sep/2026:20:18:54 +0200] "GET /..%2f..%2f.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
136.107.121.250 - - [11/Sep/2026:20:18:54 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
136.107.121.250 - - [11/Sep/2026:20:18:54 +0200] "GET /static//.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])"
136.107.121.250 - - [11/Sep/2026:20:18:54 +0200] "GET /.idea/WebServers.xml HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compati
show less
Web App Attack
Hacking
🇬🇧
thetomtaylor.co.uk
2026-09-11 18:08:00
(7 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:05:24
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.250 (250.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.250 (250.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:05:20.545640 2026] [security2:error] [pid 22246:tid 22246] [client 136.107.121.250:60954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iheldt.net"] [uri "/.env.backup"] [unique_id "aqRC4GdBQwRMKuVaG-yDlgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:42:10
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.107.121.250 (250.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.107.121.250 (250.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:42:04.140953 2026] [security2:error] [pid 2688:tid 2688] [client 136.107.121.250:56954] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ichi51e.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ichi51e.net"] [uri "/localhost.key"] [unique_id "aqQ9bGl-upRWk8zvWsy7-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
valornode
2026-09-11 17:33:26
(7 hours ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-cve-2021-41773 | A ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-cve-2021-41773 | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: US | Range: 136.107.0.0/16
show less
Brute-Force
SSH
🇩🇪
konseptit
2026-09-11 17:31:45
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.107.121.250 (US/United States/250.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.107.121.250 (US/United States/250.121.107.136.bc.googleusercontent.com)
show less
SQL Injection
🇫🇷
dynamix
2026-09-11 17:28:57
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:25:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.121.250 (250.121.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.121.250 (250.121.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:25:52.588283 2026] [security2:error] [pid 2232:tid 2232] [client 136.107.121.250:48326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hydrogenplus.net"] [uri "/.git/config"] [unique_id "aqQ5oD6MghknFuqZD5ZjVgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-11 17:10:03
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
paissangroup
2026-09-11 16:48:37
(8 hours ago)
Multiple WAF Violations
Web App Attack