๐ฉ๐ช
dbmwebdesign
2026-08-08 07:10:10
(2 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 06:44:00
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 02:43:55.104062 2026] [security2:error] [pid 13637:tid 13670] [client 136.107.203.35:50850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "docdalton.com"] [uri "/.git/config"] [unique_id "anbQK9K6PteKLbKNZ8FNzwAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-08 06:00:00
(2 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-08 05:56:47
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 01:56:42.887851 2026] [security2:error] [pid 988637:tid 988637] [client 136.107.203.35:46854] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kildarafarms.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kildarafarms.com"] [uri "/z9x8c7v6b5-debug-trigger-kildarafarms.com"] [unique_id "anbFGrnmh0XYSbZOyuop0QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 05:35:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 01:35:49.919931 2026] [security2:error] [pid 2526853:tid 2526853] [client 136.107.203.35:41688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kristinmoore.com"] [uri "/.env"] [unique_id "anbANfgHclQLOj4Vg5QdngAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-08 04:26:36
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 03:59:50
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:59:43.750699 2026] [security2:error] [pid 2824473:tid 2824473] [client 136.107.203.35:58568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kyws-lp.webserviceswest.com"] [uri "/.git/config"] [unique_id "anapr28ZDu8FCdYxT4zPGAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-08 03:18:14
(2 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 136.107.203.35 (US/United States/35. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 136.107.203.35 (US/United States/35.203.107.136.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 03:10:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:10:04.681417 2026] [security2:error] [pid 2844438:tid 2844438] [client 136.107.203.35:59844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.koreagreenrecycling.com"] [uri "/.git/config"] [unique_id "anaeDAdXLw2-diQr897HqAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-08-08 02:20:57
(2 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-08 01:50:06
(2 months ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-08-08 00:43:18
(2 months ago)
Web vulnerability probing: /dist/manifest.json
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 00:21:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.203.35 (35.203.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 20:21:03.148496 2026] [security2:error] [pid 1309262:tid 1309262] [client 136.107.203.35:34930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jbaydeliveries.com"] [uri "/public/.env"] [unique_id "anZ2b2qtXWwEMzQ_pmltCgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-08 00:07:54
(2 months ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฉ๐ช
bazter.pro
2026-08-07 23:55:38
(2 months ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack