🇧🇪
voormedia
2026-08-20 10:22:05
(3 weeks ago)
Accessed trap at '/.git/config'
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 10:17:17
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 136.108.88.126 (126.88.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.88.126 (126.88.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 06:17:14.597032 2026] [security2:error] [pid 32633:tid 32633] [client 136.108.88.126:39586] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||caferutadelaseda.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caferutadelaseda.com"] [uri "/rclone.conf"] [unique_id "aobUKktNd-Rd8DDya6Kx3wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-08-20 09:59:24
(3 weeks ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.108.88.126 (US/U ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.108.88.126 (US/United States/South Carolina/North Charleston/126.88.108.136.bc.googleusercontent.com)
show less
Bad Web Bot
🇩🇪
Skyrider
2026-08-20 09:50:20
(3 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-08-20 09:26:41
(3 weeks ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇮🇹
Inartis
2026-08-20 08:34:58
(3 weeks ago)
136.108.88.126 - - [20/Aug/2026:10:34:48 +0200] "GET /.git/config HTTP/1.1" 403 7823 "-" "Mozilla/5. ...
show more
136.108.88.126 - - [20/Aug/2026:10:34:48 +0200] "GET /.git/config HTTP/1.1" 403 7823 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
136.108.88.126 - - [20/Aug/2026:10:34:52 +0200] "GET /admin HTTP/1.1" 302 8057 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
136.108.88.126 - - [20/Aug/2026:10:34:53 +0200] "GET /admin/login HTTP/1.1" 301 362 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 06:27:09
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 136.108.88.126 (126.88.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.88.126 (126.88.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 02:27:03.954867 2026] [security2:error] [pid 17794:tid 17794] [client 136.108.88.126:38454] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tulsatvmemories.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tulsatvmemories.com"] [uri "/rclone.conf"] [unique_id "aoaeN-kxGppV5hQYnTtdewAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 06:08:41
(3 weeks ago)
Banned by Fail2Ban on server
Web App Attack
🇩🇪
Oakley
2026-08-20 05:17:17
(3 weeks ago)
(confirmed_bot_sig) Confirmed bot
Hacking
Anonymous
2026-08-20 04:55:01
(3 weeks ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-08-20 04:46:30
(3 weeks ago)
Bot detected scanning for vulnerable pages
Port Scan
Anonymous
2026-08-20 04:42:34
(3 weeks ago)
Detected by CrowdSec: crowdsecurity/http-probing
Web App Attack
🇳🇿
Antinson
2026-08-20 04:42:30
(3 weeks ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇩🇪
paissangroup
2026-08-20 03:59:39
(3 weeks ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 02:33:58
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.108.88.126 (126.88.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.88.126 (126.88.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 22:33:54.596949 2026] [security2:error] [pid 17069:tid 17069] [client 136.108.88.126:53252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexgitlin.com"] [uri "/.git/config"] [unique_id "aoZnkmLuHCriU_IL9bN_JwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack