🇺🇸
TPI-Abuse
2026-09-07 03:10:26
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.67.143.103 (103.143.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.67.143.103 (103.143.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:10:22.796451 2026] [security2:error] [pid 13412:tid 13412] [client 136.67.143.103:58630] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.andreas-villa.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.andreas-villa.com"] [uri "/rclone.conf"] [unique_id "ap4rHqOdQ0Gr9tQW6tB2EQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-07 01:44:41
(4 hours ago)
Scanning for web/db/file exploits on www.uparq.nl
SQL Injection
Bad Web Bot
Web App Attack
🇬🇧
kie
2026-09-07 00:18:13
(6 hours ago)
07-09-2026:00:17:56UTC [Nginx Web Server] Suspicious web request: path:/.aws/ path:/.git path:/.env ...
show more
07-09-2026:00:17:56UTC [Nginx Web Server] Suspicious web request: path:/.aws/ path:/.git path:/.env path:/.env,/.git (28 request(s)).
show less
Bad Web Bot
Web App Attack
🇺🇸
WellSpring
2026-09-06 22:58:14
(7 hours ago)
env leak on officialcovenant.org/@fs/src/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 22:33:56
(7 hours ago)
cloudlinux2 fail2ban: 2026-09-07 00:29:02,020 fail2ban.actions [2048]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-07 00:29:02,020 fail2ban.actions [2048]: NOTICE [plesk-modsecurity] Unban 34.71.7.109cloudlinux2 fail2ban: 2026-09-07 00:30:40,017 fail2ban.filter [2048]: INFO [plesk-wordpress] Found 173.239.218.161 - 2026-09-07 00:30:39cloudlinux2 fail2ban: 2026-09-07 00:31:29,667 fail2ban.filter [2048]: INFO [plesk-apache] Found 34.74.109.225 - 2026-09-07 00:31:29cloudlinux2 fail2ban: 2026-09-07 00:32:46,287 fail2ban.filter [2048]: INFO [plesk-wordpress] Found 136.144.33.52 - 2026-09-07 00:32:45cloudlinux2 fail2ban: 2026-09-07 00:33:16,688 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 136.67.143.103 - 2026-09-07 00:33:16cloudlinux2 fail2ban: 2026-09-07 00:33:16,788 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 136.67.143.103 - 2026-09-07 00:33:16cloudlinux2 fail2ban: 2026-09-07 00:33:16,706 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 136.67.143.103 - 2026-09-07 00:33:16cloudlinux2 fail2ban: 2
show less
Web App Attack
🇳🇱
Savvii
2026-09-06 22:27:08
(8 hours ago)
20 attempts against mh-misbehave-ban on solar
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Viveronese
2026-09-06 20:42:32
(9 hours ago)
HTTP vulnerability scanning
Web App Attack
🇫🇷
dynamix
2026-09-06 19:58:43
(10 hours ago)
Multiple WAF Violations
Web App Attack
🇧🇪
cmbplf
2026-09-06 19:30:53
(10 hours ago)
593 requests with url.path */@fs/*
179 requests with url.path */proc/*
173 requests with url.path ...
show more
593 requests with url.path */@fs/*
179 requests with url.path */proc/*
173 requests with url.path *.oci/*
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 19:08:19
(11 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.67.143.103 (103.143.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 136.67.143.103 (103.143.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:08:13.283555 2026] [security2:error] [pid 30409:tid 30409] [client 136.67.143.103:49608] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||valbreniscrivalbo.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "valbreniscrivalbo.com"] [uri "/api/fs/read"] [unique_id "ap26HS5JjBbbofnohjWvZgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 18:33:46
(11 hours ago)
136.67.143.103 - - [06/Sep/2026:20:33:44 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linu ...
show more
136.67.143.103 - - [06/Sep/2026:20:33:44 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.67.143.103 - - [06/Sep/2026:20:33:45 +0200] "GET /forgot-password HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.67.143.103 - - [06/Sep/2026:20:33:45 +0200] "GET /account/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.67.143.103 - - [06/Sep/2026:20:33:45 +0200] "GET /register HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.67.143.103 - - [06/Sep/2026:20:33:45 +0200] "GET /sign-in HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.67.143.103 - - [06/Sep/2026:20:33:45 +0200] "GET
...
show less
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-06 17:45:24
(12 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇳🇱
Savvii
2026-09-06 17:36:20
(12 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:25:09
(13 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.67.143.103 (103.143.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 136.67.143.103 (103.143.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:25:04.667518 2026] [security2:error] [pid 10767:tid 10943] [client 136.67.143.103:39706] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||paidsearchconsulting.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "paidsearchconsulting.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap2h8NN54SpjqQxOyOBwiAAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 17:05:41
(13 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack