๐ช๐ธ
masterguru
2026-09-24 02:36:41
(1 minute ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 02:25:26
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:25:20.292149 2026] [security2:error] [pid 3176:tid 3176] [client 136.66.171.141:52754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.artspacecleveland.com.artspacecleveland.org"] [uri "/storage/.env"] [unique_id "arSKENM8IK-i2wgmhVR1GgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:16:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:16:14.834311 2026] [security2:error] [pid 32192:tid 32245] [client 136.66.171.141:60200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amphoracollectors.org"] [uri "/.env.save"] [unique_id "arR53lYXU2cuwUsS9eJ17AAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 00:55:51
(1 hour ago)
164 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
๐ง๐ช
cmbplf
2026-09-24 00:40:07
(1 hour ago)
10.035 requests from abuseipdb.com blacklisted IP (1yr1mo1w)
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-09-23 23:05:30
(3 hours ago)
Too many Status 40X (16)
Scanning/Probing (13)
Brute-Force
Web App Attack
Anonymous
2026-09-23 22:01:01
(4 hours ago)
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:32:52
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:32:47.163080 2026] [security2:error] [pid 32598:tid 32598] [client 136.66.171.141:53094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "26c.org"] [uri "/.env.example"] [unique_id "arRFf6u-JHgPkqlAhL71wwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 21:16:21
(5 hours ago)
LogGuard auto-report | score=110 | flags=flood | reasons=[+35] burst_10s_hard: 186 req in 10s (thres ...
show more
LogGuard auto-report | score=110 | flags=flood | reasons=[+35] burst_10s_hard: 186 req in 10s (threshold 100); [+25] error_ratio_severe: 82% error rate in 60s (153/186); [+25] path_diversity_severe: 169 unique paths in 60s (threshold 50); [+25] probe_paths: Hit 75 known probe paths: /.aws/config, /.docker/.env, /.env, /.env.development, /.env.docker
show less
DDoS Attack
๐บ๐ธ
lavnet.net
2026-09-23 20:58:01
(5 hours ago)
136.66.171.141 - - [23/Sep/2026:20:58:01 +0000] "GET /z9x8c7v6b5-debug-trigger-a0a0.org HTTP/2.0" 40 ...
show more
136.66.171.141 - - [23/Sep/2026:20:58:01 +0000] "GET /z9x8c7v6b5-debug-trigger-a0a0.org HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
136.66.171.141 - - [23/Sep/2026:20:58:01 +0000] "GET /1ctcw20mf659qe93yzm8 HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
136.66.171.141 - - [23/Sep/2026:20:58:01 +0000] "GET /v2u1nyucsffgj2la8pvu HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
136.66.171.141 - - [23/Sep/2026:20:58:01 +0000] "POST /graphql HTTP/2.0" 404 1855 "https://a0a0.org" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.66.171.141 - - [23/Sep/2026:20:58:01 +0000] "GET /actuator/gateway/routes HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
136.66.171.141 - - [
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-23 20:40:11
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:40:05.315463 2026] [security2:error] [pid 20202:tid 20202] [client 136.66.171.141:43240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accsbg.org"] [uri "/web.config"] [unique_id "arQ5Jc1_rddJwroSwiCagQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-09-23 20:22:09
(6 hours ago)
Web app vulnerability scanning detected. Evidence: [IP] - - [23/Sep/2026:20:22:09 +0000] "GET /admin ...
show more
Web app vulnerability scanning detected. Evidence: [IP] - - [23/Sep/2026:20:22:09 +0000] "GET /admin%2F.env HTTP/1.1" 404 776 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
[IP] - - [23/Sep/2026:20:22:09 +0000] "GET /dashboard%2F.env HTTP/1.1" 404 776 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:51:34
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:51:27.537022 2026] [security2:error] [pid 20110:tid 20110] [client 136.66.171.141:44370] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ahijado.org|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ahijado.org"] [uri "/config/master.key"] [unique_id "arQtv_a4MRVgKgQPOoGkbgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:18:14
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.171.141 (141.171.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:18:11.093656 2026] [security2:error] [pid 22748:tid 22748] [client 136.66.171.141:45084] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alextra.org|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alextra.org"] [uri "/config/master.key"] [unique_id "arQl84zu5xxHv4iGSaUMfgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-23 18:40:02
(7 hours ago)
crowdsecurity/grafana-cve-2021-43798
Brute-Force
Web App Attack