🇩🇪
EGP Abuse Dept
2026-09-07 02:56:13
(2 hours ago)
Scanning for web/db/file exploits on www.webshoprestaurantamsterdammertje.nl
SQL Injection
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:39:42
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.114.55.76 (76.55.114.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.114.55.76 (76.55.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:39:35.540683 2026] [security2:error] [pid 11734:tid 11746] [client 136.114.55.76:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/rclone.conf"] [unique_id "ap4j56iqcDWugjfHnMJJ_wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 02:08:19
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 01:37:55
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.114.55.76 (76.55.114.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.114.55.76 (76.55.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:37:47.422749 2026] [security2:error] [pid 4204:tid 4204] [client 136.114.55.76:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.wiszen.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.wiszen.org"] [uri "/rclone.conf"] [unique_id "ap4Va4K8f6RW-K0sNSzM3AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:16:06
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.114.55.76 (76.55.114.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.114.55.76 (76.55.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:15:58.976984 2026] [security2:error] [pid 14768:tid 14768] [client 136.114.55.76:45996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vaghyst.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vaghyst.com"] [uri "/ssl/server.key"] [unique_id "ap4QTgWumbYKe_kvOIgpUQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:55:25
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.55.76 (76.55.114.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.55.76 (76.55.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:55:18.861600 2026] [security2:error] [pid 15530:tid 15530] [client 136.114.55.76:60458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tiesidebikinis.com"] [uri "/%2e%2e/.env"] [unique_id "ap23Flk7JsMmwLcWwoRZjQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:57:54
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.55.76 (76.55.114.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.55.76 (76.55.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:57:49.326741 2026] [security2:error] [pid 14467:tid 14467] [client 136.114.55.76:46862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oxygenfarm.com"] [uri "/@fs/var/task/.env"] [unique_id "ap2pnSbGvLS7UkcAQv4YzgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 17:07:14
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
Mehmet_The_Script_Kiddie
2026-09-06 15:22:21
(14 hours ago)
CloudFlare WAF REPORT: /api/fs/read?path=/proc/self/environ&allowOutsideWorkspace=true
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 15:02:59
(14 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:12:03
(15 hours ago)
(mod_security) mod_security (id:243320) triggered by 136.114.55.76 (76.55.114.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:243320) triggered by 136.114.55.76 (76.55.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:11:56.391794 2026] [security2:error] [pid 17680:tid 17680] [client 136.114.55.76:44772] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||app.sympalais.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "app.sympalais.com"] [uri "/.profile"] [unique_id "ap10rPLs9WHbbLWXzGbRHAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:53:59
(15 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.114.55.76 (76.55.114.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 136.114.55.76 (76.55.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:53:53.211665 2026] [security2:error] [pid 943:tid 943] [client 136.114.55.76:54976] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.ronelgas.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.ronelgas.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap1wcTT7Qpoc7los7wjHDAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:20:42
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.55.76 (76.55.114.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.55.76 (76.55.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:20:38.879797 2026] [security2:error] [pid 25202:tid 25202] [client 136.114.55.76:48576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summitartists.com"] [uri "/api/.env/public/.env"] [unique_id "ap1opiKRTQG7Nfjh0SzqwgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-06 13:18:23
(16 hours ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-09-06 13:17:40
(16 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack