🇺🇸
TPI-Abuse
2026-09-12 08:29:30
(34 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:29:25.778459 2026] [security2:error] [pid 24220:tid 24220] [client 136.107.137.45:35584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.ionekotis.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.ionekotis.net"] [uri "/rclone.conf"] [unique_id "aqUNZabNCL8HEOZb7xrn-QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 19:20:02
(13 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
🇺🇸
mnsf
2026-09-11 19:05:33
(13 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-11 18:59:52
(14 hours ago)
20 attempts against mh-misbehave-ban on pf102962
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-11 18:54:24
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:42:52
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:42:44.871696 2026] [security2:error] [pid 742:tid 742] [client 136.107.137.45:51608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kidswow.net"] [uri "/api/.env/public/.env"] [unique_id "aqRLpPtnLdhR3Yt47NrwKQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-11 18:20:17
(14 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:18:35
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:18:28.167958 2026] [security2:error] [pid 4751:tid 4751] [client 136.107.137.45:42046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katemcleod.net"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqRF9GOPX-La92pAI-GIiQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-11 18:07:24
(14 hours ago)
136.107.137.45 - - [11/Sep/2026:20:07:21 +0200] "GET /.dockerenv HTTP/2.0" 404 288 "-" "Mozilla/5.0 ...
show more
136.107.137.45 - - [11/Sep/2026:20:07:21 +0200] "GET /.dockerenv HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
136.107.137.45 - - [11/Sep/2026:20:07:21 +0200] "GET /var/run/secrets/kubernetes.io/serviceaccount/token HTTP/2.0" 404 288 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
136.107.137.45 - - [11/Sep/2026:20:07:21 +0200] "POST /v1/graphql HTTP/2.0" 404 288 "https://[site]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
136.107.137.45 - - [11/Sep/2026:20:07:21 +0200] "GET /proc/self/cgroup HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
136.107.137.45 - - [11/Sep/2026:20:07:21 +0200] "GET /.env?raw HTTP/2.0" 404 288 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
136.107.137.45 - - [11
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 17:57:41
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:57:36.101385 2026] [security2:error] [pid 2356:tid 2356] [client 136.107.137.45:35196] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||k0cgy.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "k0cgy.net"] [uri "/rclone.conf"] [unique_id "aqRBENGHElAoDD7CmJbapQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 17:46:12
(15 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:36:07
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:36:01.529540 2026] [security2:error] [pid 3895:tid 3895] [client 136.107.137.45:57750] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jresm.net|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jresm.net"] [uri "/.env.backup"] [unique_id "aqQ8AaPJ3-pBOBVUqGqypgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:16:15
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:16:08.081707 2026] [security2:error] [pid 29817:tid 29817] [client 136.107.137.45:41730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jmnr.net"] [uri "/@fs/.env"] [unique_id "aqQ3WHfbtUHN33LyTiwNNgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-11 17:00:35
(16 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:57:41
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.137.45 (45.137.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:57:31.399313 2026] [security2:error] [pid 1930:tid 1930] [client 136.107.137.45:54988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerryglass.net"] [uri "/.git/config"] [unique_id "aqQy-_xbN3mqnDiJ1GVwdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack