๐บ๐ธ
TPI-Abuse
2026-10-08 19:14:24
(2 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.69.148.72 (72.148.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.148.72 (72.148.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:14:17.649896 2026] [security2:error] [pid 29879:tid 29927] [client 136.69.148.72:57126] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||draginich.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "draginich.com"] [uri "/z9x8c7v6b5-debug-trigger-draginich.com"] [unique_id "asfriaNPK-5u11AV1c9m-gAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-10-08 19:05:56
(10 minutes ago)
AetherFox VoidGuard detected: [Thu Oct 08 19:05:55.312943 2026] [authz_core:error] [pid 1897588:tid ...
show more
AetherFox VoidGuard detected: [Thu Oct 08 19:05:55.312943 2026] [authz_core:error] [pid 1897588:tid 1897624] [client 136.69.148.72:42144] AH01630: client denied by server configuration: proxy:https://[MASKED]/bt83z8h6q3okuc7cbvp0
[Thu Oct 08 19:05:55.324637 2026] [authz_core:error] [pid 1897588:tid 1897631] [client 136.69.148.72:42142] AH01630: client denied by server configuration: proxy:https://[MASKED]/z9x8c7v6b5-debug-trigger-draconigen.net
[Thu Oct 08 19:05:55.326523 2026] [authz_core:error] [pid 1897588:tid 1897641] [client 136.69.148.72:42182] AH01630: client denied by server configuration: proxy:https://[MASKED]/lib/terminal-xhr.php
[Thu Oct 08 19:05:55.328057 2026] [authz_core:error] [pid 1897588:tid 1897635] [client 136.69.148.72:42166] AH01630: client denied by server configuration: proxy:https://[MASKED]/e9x60jsbtnuyjhboz5d5
[Thu Oct 08 19:05:55.934829 2026] [authz_core:error] [pid 1897588:tid 1897627] [client 136.69.148.72:42224] AH01630: cl
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-10-08 18:34:04
(42 minutes ago)
Bad behaviour
Web Spam
๐ซ๐ท
dynamix
2026-10-08 18:25:12
(51 minutes ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
VHosting
2026-10-08 18:20:03
(56 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-10-08 18:19:18
(57 minutes ago)
Repeated requests for suspicious nonexistent URLs, for example: /login (HTTP/2.0 port 443, user agen ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /login (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 18:14:37
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 136.69.148.72 (72.148.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.148.72 (72.148.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:14:31.011300 2026] [security2:error] [pid 4185:tid 4185] [client 136.69.148.72:55904] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dpcfab.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dpcfab.com"] [uri "/z9x8c7v6b5-debug-trigger-dpcfab.com"] [unique_id "asfdh7yF3OJyKSW-WUBd_QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-08 18:14:08
(1 hour ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-08 18:03:06
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1248
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 18:01:29
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-08 18:01:07
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php
Query: ?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input
Timestamp: 2026-10-08T17:32:21Z
Ray ID: a476e2678adf52ff
UA: Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 17:44:23
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 136.69.148.72 (72.148.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.148.72 (72.148.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:44:20.305864 2026] [security2:error] [pid 7497:tid 7497] [client 136.69.148.72:48616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||dhappraisalservices.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dhappraisalservices.com"] [uri "/z9x8c7v6b5-debug-trigger-dhappraisalservices.com"] [unique_id "asfWdKNAKKJl9uHFI-ypgwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-10-08 17:42:26
(1 hour ago)
(web_sensitive_file) srv104 Sensitive file probe (.env/.git/backup) 136.69.148.72 (US/United States/ ...
show more
(web_sensitive_file) srv104 Sensitive file probe (.env/.git/backup) 136.69.148.72 (US/United States/72.148.69.136.bc.googleusercontent.com): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 17:28:48
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.69.148.72 (72.148.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.69.148.72 (72.148.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:28:43.550066 2026] [security2:error] [pid 14461:tid 14461] [client 136.69.148.72:45388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brushmileage.org"] [uri "/files../.env"] [unique_id "asfSy3hUkTYqL-T8UmAL2wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-08 17:28:39
(1 hour ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.wtf | URI: /.vite/manifest.json | UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack