🇳🇱
Savvii
2026-09-11 18:42:30
(2 hours ago)
20 attempts against mh_ha-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 18:27:50
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
ruusvuu
2026-09-11 18:23:01
(2 hours ago)
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /wp-json, /v1 ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /wp-json, /v1/graphql.
Sample log lines:
[shots] 📊 9/11/2026, 11:22:59 136.66.85.43 GET /wp-json 403 - 0.509 ms
[shots] 📊 9/11/2026, 11:23:00 136.66.85.43 POST /v1/graphql 429 - 0.588 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
🇳🇱
Savvii
2026-09-11 18:18:30
(2 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-11 17:33:49
(3 hours ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:33:37
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:33:33.419608 2026] [security2:error] [pid 15123:tid 15123] [client 136.66.85.43:46760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rimbey.us"] [uri "/.svn/entries"] [unique_id "aqQ7bfRWf2dOa--MUxbSDQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:15:51
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:15:45.363520 2026] [security2:error] [pid 2217522:tid 2217531] [client 136.66.85.43:37190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "priyom.us"] [uri "/@fs/.env"] [unique_id "aqQ3QS2ChxZfYxBtuDWXhwAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:00:45
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:00:41.085185 2026] [security2:error] [pid 15033:tid 15033] [client 136.66.85.43:59776] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||passy.us|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "passy.us"] [uri "/rclone.conf"] [unique_id "aqQzuStbQdbrkW23Nmz5rQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-11 17:00:33
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
SketchyDude
2026-09-11 16:55:31
(4 hours ago)
Banned by Fail2Ban jail: apache-fakegooglebot
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 16:37:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:36:56.884742 2026] [security2:error] [pid 1129:tid 1129] [client 136.66.85.43:36514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nashhouse.us"] [uri "/.env"] [unique_id "aqQuKBQ18SknmBKVi9kjLgAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-11 16:30:04
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:17:18
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.85.43 (43.85.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:17:14.342262 2026] [security2:error] [pid 17508:tid 17508] [client 136.66.85.43:48968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marv.us"] [uri "/.env"] [unique_id "aqQpiqZrFsS-bpQfzf320gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 16:08:42
(5 hours ago)
136.66.85.43 - - [11/Sep/2026:12:08:42 -0400] "GET /settings%2F.env HTTP/1.1" 404 460 "-" "Mozilla/5 ...
show more
136.66.85.43 - - [11/Sep/2026:12:08:42 -0400] "GET /settings%2F.env HTTP/1.1" 404 460 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
Web App Attack
SSH
🇺🇸
mnsf
2026-09-11 16:06:13
(5 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack