๐บ๐ธ
TPI-Abuse
2026-09-30 14:59:28
(16 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:59:22.640561 2026] [security2:error] [pid 6596:tid 6596] [client 136.118.3.43:34704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wa211.org"] [uri "/wp-config.php~"] [unique_id "ar0jyg3hQbNwjkwlvJU2RgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-30 14:32:07
(44 minutes ago)
Scan of vulnerable files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:22:34
(53 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:22:26.970643 2026] [security2:error] [pid 14132:tid 14132] [client 136.118.3.43:60596] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||rharano.org|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rharano.org"] [uri "/server.key"] [unique_id "ar0bImBoQnRdC5ekCVbg4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 14:12:14
(1 hour ago)
Honey Pot Hit / Attack Vector found!
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:27:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:27:28.831971 2026] [security2:error] [pid 16562:tid 16562] [client 136.118.3.43:58284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rudiscreations.org"] [uri "/.htpasswd"] [unique_id "ar0AMAIpLhW-S2PdCM_W3QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
creechy
2026-09-30 11:22:54
(3 hours ago)
136.118.3.43 - - [30/Sep/2026:04:22:49 -0700] "GET /api%2F.env HTTP/1.1" 400 842 "-" "Mozilla/5.0 (c ...
show more
136.118.3.43 - - [30/Sep/2026:04:22:49 -0700] "GET /api%2F.env HTTP/1.1" 400 842 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Hacking
Bad Web Bot
๐ซ๐ท
IRISIO
2026-09-30 11:03:17
(4 hours ago)
scans/SQL injection/spam posts : 683 queries
Web App Attack
SQL Injection
Anonymous
2026-09-30 11:00:06
(4 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
ghostwarriors
2026-09-30 10:50:11
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-30 10:49:32
(4 hours ago)
136.118.3.43 - - [30/Sep/2026:12:49:29 +0200] "GET /static//app/.env HTTP/2.0" 403 293 "-" "Mozilla/ ...
show more
136.118.3.43 - - [30/Sep/2026:12:49:29 +0200] "GET /static//app/.env HTTP/2.0" 403 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email])"
136.118.3.43 - - [30/Sep/2026:12:49:29 +0200] "GET /api/v1/config HTTP/2.0" 404 289 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
136.118.3.43 - - [30/Sep/2026:12:49:29 +0200] "GET /static//home/user/.env HTTP/2.0" 404 289 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
136.118.3.43 - - [30/Sep/2026:12:49:29 +0200] "GET /.env?import&raw HTTP/2.0" 404 289 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
136.118.3.43 - - [30/Sep/2026:12:49:29 +0200] "GET /.//.env HTTP/2.0" 404 289 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
136.118.3.43 - - [30/Sep/2026:12:49:29 +0200] "GET /.env.local?raw HTTP/2.0" 404 289 "-" "DuckAssistBot/1.1 (https://duckduckgo.c
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 10:34:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:34:01.292363 2026] [security2:error] [pid 2303:tid 2303] [client 136.118.3.43:54238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "helpkccare.org"] [uri "/.env.js"] [unique_id "arzlmeCV9qU-sbRQuYyO3AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 10:30:04
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:14:28
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.3.43 (43.3.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:14:22.711303 2026] [security2:error] [pid 5193:tid 5193] [client 136.118.3.43:54092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cain2016.org"] [uri "/.htpasswd"] [unique_id "arzg_iz1g4H5cBhdzZIzrQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 09:57:45
(5 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-30 09:56:55
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking