πΊπΈ
TPI-Abuse
2026-10-02 18:37:01
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.128.7 (7.128.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.128.7 (7.128.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:36:55.599921 2026] [security2:error] [pid 26098:tid 26185] [client 136.108.128.7:37552] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||prismatik.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "prismatik.com"] [uri "/z9x8c7v6b5-debug-trigger-prismatik.com"] [unique_id "ar_5xx6bh-Mm8VkQ29zqxQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
simpeg-adm.bandung.go.id
2026-10-02 18:11:26
(3 hours ago)
02/Oct/2026:18:11:25 +0000;136.108.128.7;"/lib/terminal-xhr.php"
02/Oct/2026:18:11:25 +0000;136.108. ...
show more
02/Oct/2026:18:11:25 +0000;136.108.128.7;"/lib/terminal-xhr.php"
02/Oct/2026:18:11:25 +0000;136.108.128.7;"/model/info"
02/Oct/2026:18:11:25 +0000;136.108.128.7;"/lrp5jle02iy9xout6nr8"
02/Oct/2026:18:11:25 +0000;136.108.128.7;"/tarzss2jjucr5g6e50g3"
02/Oct/2026:18:11:25 +0000;136.108.128.7;"/z9x8c7v6b5-debug-trigger-app.jinalgovindphotography.com"
02/Oct/2026:18:11:25 +0000;136.108.128.7;"/dist/manifest.json"
02/Oct/2026:18:11:25 +0000;136.108.128.7;"/.vite/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 17:27:55
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.128.7 (7.128.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.128.7 (7.128.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:27:51.038523 2026] [security2:error] [pid 11082:tid 11082] [client 136.108.128.7:38228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jeffreycopeland.com"] [uri "/css../.env"] [unique_id "ar_pl1_w-MZI7wZAkp15ZQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
Cloudkul Cloudkul
2026-10-02 17:12:23
(4 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 15:35:22
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.128.7 (7.128.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.128.7 (7.128.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:35:18.100151 2026] [security2:error] [pid 27425:tid 27425] [client 136.108.128.7:37814] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jdeloa.com|F|2"] [data ".jdeloa.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jdeloa.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jdeloa.com"] [unique_id "ar_PNo9nMCBkBc90kKdvawAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 14:50:20
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.128.7 (7.128.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.128.7 (7.128.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:50:17.355894 2026] [security2:error] [pid 25351:tid 25389] [client 136.108.128.7:35714] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jeffgolden.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeffgolden.com"] [uri "/z9x8c7v6b5-debug-trigger-jeffgolden.com"] [unique_id "ar_Eqb6Nda9ADooHc5hMLQAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Thibault Millant
2026-10-02 13:53:36
(7 hours ago)
136.108.128.7 - - [02/Oct/2026:13:53:04 +0000] "-" 400 150 "-" "-"
136.108.128.7 - - [02/Oct/2026:13 ...
show more
136.108.128.7 - - [02/Oct/2026:13:53:04 +0000] "-" 400 150 "-" "-"
136.108.128.7 - - [02/Oct/2026:13:53:04 +0000] "-" 400 150 "-" "-"
136.108.128.7 - - [02/Oct/2026:13:53:04 +0000] "-" 400 150 "-" "-"
136.108.128.7 - - [02/Oct/2026:13:53:04 +0000] "-" 400 150 "-" "-"
136.108.128.7 - - [02/Oct/2026:13:53:04 +0000] "-" 400 150 "-" "-"
...
show less
Brute-Force
Exploited Host
SSH
πΊπΈ
TPI-Abuse
2026-10-02 13:51:39
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.128.7 (7.128.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.128.7 (7.128.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:51:35.776507 2026] [security2:error] [pid 11231:tid 11231] [client 136.108.128.7:41702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.infojeffreysbay.com"] [uri "/.env.js"] [unique_id "ar-254e0nrxJolsRnE5JkQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
updown.io
2026-10-02 09:15:04
(12 hours ago)
{"level":"info","ts":1790932502.29235,"logger":"http.log.access.log1","msg":"handled request","reque ...
show more
{"level":"info","ts":1790932502.29235,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.108.128.7","remote_port":"51872","client_ip":"136.108.128.7","proto":"HTTP/2.0","method":"GET","host":"status.rezcomm.com","uri":"/","headers":{"Sec-Fetch-Mode":["navigate"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Priority":["u=0, i"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""],"X-Nextjs-Data":["1"],"Sec-Fetch-User":["?1"],"Sec-Ch-Ua-Mobile":["?0"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Sec-Fetch-Site":["none"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Accept-Language":["en-US,en;q=0.9"],"Accept":["text/html,appli
...
show less
DDoS Attack
Web App Attack
π¨π
dalslab ltd
2026-10-02 08:48:41
(12 hours ago)
[02/Oct/2026:10:48:40 +0200] - 404 404 - GET https auth.dalslab.com "/.vite/manifest.json" [Client 1 ...
show more
[02/Oct/2026:10:48:40 +0200] - 404 404 - GET https auth.dalslab.com "/.vite/manifest.json" [Client 136.108.128.7] [Length 1598] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-"
[02/Oct/2026:10:48:40 +0200] - 404 404 - GET https auth.dalslab.com "/dzh6t80pyjq4pc99ss93" [Client 136.108.128.7] [Length 1598] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-"
[02/Oct/2026:10:48:40 +0200] - 404 404 - GET https auth.dalslab.com "/z9x8c7v6b5-debug-trigger-auth.dalslab.com" [Client 136.108.128.7] [Length 1600] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-"
[02/Oct/2026:10:48:40 +0200] - 403 403 - POST https auth.dalslab.com "/" [Client 136.108.128.7] [Length 959] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatib
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-10-02 08:05:33
(13 hours ago)
Abuse Detected (1)
Brute-Force
Web App Attack
Anonymous
2026-10-02 08:01:26
(13 hours ago)
Web App Attack
π³π±
e.fierstra
2026-10-02 08:00:23
(13 hours ago)
excessive HTTP 404 errors
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-02 07:11:51
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.128.7 (7.128.108.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.128.7 (7.128.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:11:47.659382 2026] [security2:error] [pid 215647:tid 215647] [client 136.108.128.7:48634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.johngutierrez.com|F|2"] [data ".johngutierrez.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.johngutierrez.com"] [uri "/z9x8c7v6b5-debug-trigger-www.johngutierrez.com"] [unique_id "ar9ZMzKOFAWhdapQ-p13owAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 06:36:01
(14 hours ago)
malicious scanning tool activity
Web App Attack