๐บ๐ธ
TPI-Abuse
2026-09-21 06:36:36
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.110.59.82 (82.59.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.110.59.82 (82.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:36:29.759641 2026] [security2:error] [pid 14204:tid 14250] [client 136.110.59.82:47284] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.jomega.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.jomega.org"] [uri "/rclone.conf"] [unique_id "arDQbcK6ewrfRUk0Hk-uGgAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
technojoe99
2026-09-21 04:27:59
(1 day ago)
Exploit scan from 136.110.59.82. GET /z9x8c7v6b5-debug-trigger-develop.cup-of-joe.org HTTP/2.0.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:14:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.59.82 (82.59.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.59.82 (82.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:14:36.478148 2026] [security2:error] [pid 27710:tid 27710] [client 136.110.59.82:37528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.flinthillsveterans.org"] [uri "/.env.development"] [unique_id "arCvLK8-wuQ3V-fniLn4DgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:43:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.110.59.82 (82.59.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.110.59.82 (82.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:43:15.294108 2026] [security2:error] [pid 5068:tid 5068] [client 136.110.59.82:60000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.forerunnersjazz.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.forerunnersjazz.org"] [uri "/rclone.conf"] [unique_id "arCn00ZMiiyO_Cjb3KxVJQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 03:39:48
(1 day ago)
[Mon Sep 21 05:39:46.077535 2026] [access_compat:error] [pid 3854349:tid 3854349] [client 136.110.59 ...
show more
[Mon Sep 21 05:39:46.077535 2026] [access_compat:error] [pid 3854349:tid 3854349] [client 136.110.59.82:0] AH01797: client denied by server configuration: /var/www/wordpress/cleanextraction/.gitconfig
[Mon Sep 21 05:39:46.104530 2026] [access_compat:error] [pid 3854343:tid 3854343] [client 136.110.59.82:0] AH01797: client denied by server configuration: /var/www/wordpress/cleanextraction/.git-credentials
[Mon Sep 21 05:39:47.089095 2026] [access_compat:error] [pid 3854314:tid 3854314] [client 136.110.59.82:0] AH01797: client denied by server configuration: /var/www/wordpress/cleanextraction/.env.save
[Mon Sep 21 05:39:47.096598 2026] [access_compat:error] [pid 3854343:tid 3854343] [client 136.110.59.82:0] AH01797: client denied by server configuration: /var/www/wordpress/cleanextraction/.env.live
[Mon Sep 21 05:39:47.098274 2026] [access_compat:error] [pid 3845218:tid 3845218] [client 136.110.59.82:0] AH01797: client denied by server configuration: /var/www/wordpress/cleanextraction/.e
...
show less
Web Spam
Web App Attack
๐บ๐ธ
WPJoe
2026-09-21 03:38:27
(1 day ago)
136.110.59.82 - - [21/Sep/2026:03:38:25 +0000] "GET /.ssh/id_rsa HTTP/1.1" 403 4347 "-" "Mozilla/5.0 ...
show more
136.110.59.82 - - [21/Sep/2026:03:38:25 +0000] "GET /.ssh/id_rsa HTTP/1.1" 403 4347 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
136.110.59.82 - - [21/Sep/2026:03:38:27 +0000] "GET /.ssh/id_ed25519 HTTP/1.1" 403 410 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 03:27:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.59.82 (82.59.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.59.82 (82.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:26:55.840371 2026] [security2:error] [pid 17618:tid 17618] [client 136.110.59.82:39182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cmabiblequizzing.org"] [uri "/userfiles"] [unique_id "arCj_5gCGuL-2DzsmSYRLQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:18:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.110.59.82 (82.59.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.59.82 (82.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:18:21.243933 2026] [security2:error] [pid 22868:tid 22868] [client 136.110.59.82:50696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gardenstateakitaclub.org"] [uri "/js../.env"] [unique_id "arCT7Z1VKTInB36bPzulEgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 02:10:03
(2 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
nyt
2026-09-21 01:28:38
(2 days ago)
Sensitive File Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:17:40
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.110.59.82 (82.59.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.110.59.82 (82.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:17:35.915841 2026] [security2:error] [pid 30767:tid 30767] [client 136.110.59.82:56118] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.covid19.mavikalem.org|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.covid19.mavikalem.org"] [uri "/ssl/server.key"] [unique_id "arCFr_Cp4RlggmskII-UtwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:25:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.110.59.82 (82.59.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.59.82 (82.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:25:38.071828 2026] [security2:error] [pid 30457:tid 30457] [client 136.110.59.82:55392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thenewplace.org"] [uri "/.git/HEAD"] [unique_id "arBrcmdxaiZYfM7j5gevBQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-09-20 23:09:53
(2 days ago)
[Mon Sep 21 01:09:51.929638 2026] [security2:error] [pid 1217322:tid 1217340] [client 136.110.59.82: ...
show more
[Mon Sep 21 01:09:51.929638 2026] [security2:error] [pid 1217322:tid 1217340] [client 136.110.59.82:0] [client 136.110.59.82] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "intl.mmn.ca"] [uri "/api"] [unique_id "arBnv8xpjgJuTxtWepCUnwAAAFA"]
[Mon Sep 21 01:09:52.994966 2026] [security2:error] [pid 1217322:tid 1217344] [client 136.110.59.82:0] [client 136.110.59.82] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-ev
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 23:04:26
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.110.59.82 (82.59.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.110.59.82 (82.59.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:04:19.720122 2026] [security2:error] [pid 8452:tid 8452] [client 136.110.59.82:36748] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.centralbaptistalcoa.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.centralbaptistalcoa.org"] [uri "/rclone.conf"] [unique_id "arBmc8Ii8qQaBmXaQIA3zwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
technojoe99
2026-09-20 22:53:20
(2 days ago)
Exploit scan from 136.110.59.82. GET /.gitlab-ci.yml HTTP/2.0.
Web App Attack