๐ณ๐ฑ
Site.eu
2026-10-01 17:32:42
(3 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-01 17:12:28
(3 days ago)
apache vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:24:12
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 136.66.39.143 (143.39.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.39.143 (143.39.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:24:07.771147 2026] [security2:error] [pid 15725:tid 15725] [client 136.66.39.143:32792] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.unionega.com|F|2"] [data ".unionega.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.unionega.com"] [uri "/z9x8c7v6b5-debug-trigger-www.unionega.com"] [unique_id "ar6JJzICTu_BLO6Nb3uZWAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-01 15:22:00
(3 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐ณ๐ฑ
maxxsense
2026-10-01 15:17:17
(3 days ago)
136.66.39.143 (US/United States/143.39.66.136.bc.googleusercontent.com), more than 10 Apache 403 hit ...
show more
136.66.39.143 (US/United States/143.39.66.136.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 15:05:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 136.66.39.143 (143.39.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.39.143 (143.39.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:05:42.861640 2026] [security2:error] [pid 8395:tid 8395] [client 136.66.39.143:58104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adoniahenterprises.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adoniahenterprises.com"] [uri "/z9x8c7v6b5-debug-trigger-adoniahenterprises.com"] [unique_id "ar52xqxR-fhyrbPS8IWirwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-01 14:38:55
(3 days ago)
136.66.39.143 - - [01/Oct/2026:15:38:53 +0100] "GET /roundcube/build/manifest.json HTTP/2.0" 404 994 ...
show more
136.66.39.143 - - [01/Oct/2026:15:38:53 +0100] "GET /roundcube/build/manifest.json HTTP/2.0" 404 994 "https://webmail.alzulej.pt/build/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
show less
Bad Web Bot
๐ฉ๐ช
rh24
2026-10-01 14:06:58
(3 days ago)
(badbots) Bad bot user-agent [redacted] from 136.66.39.143 (US/United States/143.39.66.136.bc.google ...
show more
(badbots) Bad bot user-agent [redacted] from 136.66.39.143 (US/United States/143.39.66.136.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 14:04:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.66.39.143 (143.39.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.39.143 (143.39.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:04:19.416884 2026] [security2:error] [pid 11710:tid 11712] [client 136.66.39.143:50864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aisapy.com"] [uri "/files../.env"] [unique_id "ar5oY4TzA043BtsmzAJy3wAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:45:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.66.39.143 (143.39.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.39.143 (143.39.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:45:07.515735 2026] [security2:error] [pid 26851:tid 26951] [client 136.66.39.143:41538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.adprosfla.com"] [uri "/media../.env"] [unique_id "ar5j43sRa9pGRKta8tDKfgAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:23:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 136.66.39.143 (143.39.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.39.143 (143.39.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:23:42.535381 2026] [security2:error] [pid 16536:tid 16536] [client 136.66.39.143:38184] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||new.angelabcomics.com|F|2"] [data ".angelabcomics.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "new.angelabcomics.com"] [uri "/z9x8c7v6b5-debug-trigger-new.angelabcomics.com"] [unique_id "ar5e3hW2F-CRpXyyiQwAdAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-10-01 12:47:03
(3 days ago)
Attempted access to sensitive endpoint (/login) detected. Automated scan or unauthorized probing.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:37:01
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 136.66.39.143 (143.39.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.39.143 (143.39.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:36:53.445905 2026] [security2:error] [pid 5260:tid 5260] [client 136.66.39.143:44262] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||allseniorsolutions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "allseniorsolutions.com"] [uri "/z9x8c7v6b5-debug-trigger-allseniorsolutions.com"] [unique_id "ar5T5Xyoc_1oNzOSJZw3DwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Host One
2026-10-01 12:15:40
(3 days ago)
[Honeypot] Malicious activity detected by honeypot on port 80. IP attempted unauthorized access to d ...
show more
[Honeypot] Malicious activity detected by honeypot on port 80. IP attempted unauthorized access to decoy service. Original message: Web honeypot: 438 malicious requests. Attack types: file_inclusion, admin_scan, vulnerability_scan, generic_scan, wordpress_scan. Sample: GET / HTTP/2.0. Attempted credentials captured.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:14:47
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.66.39.143 (143.39.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.39.143 (143.39.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:14:42.167900 2026] [security2:error] [pid 19803:tid 19803] [client 136.66.39.143:33984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.armrms.com"] [uri "/.env.dev"] [unique_id "ar5OspV-qyI22dHmfhmtBgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack